Skip to content

Malware

Roboto

P2P Botnet discovered by Netlab360. The botnet infects linux servers via the Webmin RCE vulnerability (CVE-2019-15107) which allows attackers to run malicious code with root privileges and take over o

Roboto is a Linux malware family.

Background

A peer-to-peer botnet uncovered by Netlab360. It compromises Linux servers by exploiting the Webmin RCE flaw (CVE-2019-15107), which lets attackers execute malicious code as root and seize control of older Webmin builds. Per Netlab360's analysis, the botnet primarily offers 7 functions: reverse shell, self-uninstall, collecting a process's network information, collecting bot information, executing system commands, running encrypted files pointed to by URLs, and four DDoS techniques: ICMP Flood, HTTP Flood, TCP Flood, and UDP Flood.


Source: Malpedia (Fraunhofer FKIE).