ZeroBot

Aliases: ZeroStresser

First seen
2022-05-01 00:00:00
Malware type
botnet, ddos
Family
Malware family
Profile updated
2026-07-07 14:31:31

Targeted industries: energy-and-utilities technology-and-telecommunications government-and-public-sector

Context

ZeroBot is a Go-based botnet that spreads primarily through IoT and web application vulnerabilities. It is offered as malware as a service (MaaS) and infrastructure overlaps with DDoS-for-hire services seized by the FBI in December 2022.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Bot_Lin_Zerobot_Dec22 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Zerobot (report)
  • Microsoft — Microsoft Research Uncovers New Zerobot Capabilities (report)

External references