Roboto
- Malware type
- botnet, ddos
- Family
- Malware family
- Profile updated
- 2026-07-07 14:29:27
Context
P2P Botnet discovered by Netlab360. The botnet infects linux servers via the Webmin RCE vulnerability (CVE-2019-15107) which allows attackers to run malicious code with root privileges and take over older Webmin versions. Based on the Netlabs360 analysis, the botnet serves mainly 7 functions: reverse shell, self-uninstall, gather process' network information, gather Bot information, execute system commands, run encrypted files specified in URLs and four DDoS attack methods: ICMP Flood, HTTP Flood, TCP Flood, and UDP Flood.
Exploited vulnerabilities
- CVE-2019-15107 (vulnerability)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Roboto (report)
- blog.netlab.360.com — The Awaiting Roboto Botnet En (report)
- zdnet.com — New Roboto Botnet Emerges Targeting Linux Servers Running Webmin (report)