EnemyBot Linux Botnet Now Exploits Web Server, Android and CMS Vuln...

Advisories

Discover Hacks/Cracks News

EnemyBot Linux Botnet Now Exploits Web Server, Android and CMS Vulnerabilities

11.Locks IsometricPattern

A nascent Linux-based botnet named Enemybot has expanded its capabilities to include recently disclosed security vulnerabilities in its arsenal to target web servers, Android devices, and content management systems (CMS).

"The malware is rapidly adopting one-day vulnerabilities as part of its exploitation capabilities," AT&T Alien Labs said in a technical write-up published last week. "Services such as VMware Workspace ONE, Adobe ColdFusion, WordPress, PHP Scriptcase and more are being targeted as well as IoT and Android devices."

First disclosed by Securonix in March and later by Fortinet, Enemybot has been linked to a threat actor tracked as Keksec (aka Kek Security, Necro, and FreakOut), with early attacks targeting routers from Seowon Intech, D-Link, and iRZ.

We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.