EnemyBot , a recently discovered botnet based on code from multiple pieces of malware, is expanding its reach, exploiting critical vulnerabilities recently revealed in web servers, content management systems, IoT and Android devices .
The botnet was first discovered in March, and shortly thereafter Fortinet analyzed some samples that showed it was already exploiting flaws for more than a dozen architectures, including arm, bsd, x64, and x86.
See also: Clop ransomware: Makes a strong comeback - Over 20 victims in one month

According to the Github repository, EnemyBot draws its source code from multiple botnets. The original botnet code used by EnemyBot includes elements from: Mirai, Qbot, and Zbot.
Its main goal is to carry out distributed denial-of-service (DDoS) attacks, while it also has capabilities that allow it to scan for new target devices and infect them.
EnemyBot: New features and capabilities
A new report from AT&T Alien Labs notes that the latest variants of EnemyBot incorporate exploits for 24 vulnerabilities. Most of them are critical, but there are also some that don't even have a CVE number. This makes it even more difficult to implement protection measures.
In April, most of the vulnerabilities exploited by the EnemyBot botnet involved routers and IoT devices, with CVE-2022-27226 (iRZ) and CVE-2022-25075 (TOTOLINK) being among the most recent and Log4Shell being the most serious.

However, a new variant analyzed by AT&T Alien Labs included exploits for the following bugs:
CVE-2022-22954: Critical (CVSS: 9.8) remote code execution vulnerability affecting VMware Workspace ONE Access and VMware Identity Manager. The PoC (proof of concept) exploit was released in April 2022.
CVE-2022-22947: Another remote code execution vulnerability in Spring. It was patched as a zero-day in March 2022 and was widely exploited in April 2022.
CVE-2022-1388: Critical (CVSS: 9.8) remote code execution vulnerability affecting F5 BIG-IP, threatening vulnerable endpoints with device takeover. The first PoCs appeared in May 2022 and active exploitation began almost immediately.
See also: Update for VMware authentication bypass bug
Looking at the list of supported commands from newer versions of EnemyBot, one can spot RSHELL , which is used to create a reverse shell on the infected system. This allows attackers to bypass firewall restrictions and gain access to the compromised machine.
It is worth noting that all the other commands that appeared in the previous version are still there, so EnemyBot has a lot of options when it comes to attacks .

As stated in previous analyses, the EnemyBot botnet has been linked to the Keksec, which specializes in DDoS attacks and crypto-mining.
In November 2021, researchers from Qihoo 360 attributed Keksec to developing botnets for different platforms, including Windows and Linux:
- Linux-based botnets: Tsunami and Gafgyt
- Windows-based botnets: DarkIRC, DarkHTTP
- Dual systems: Necro (developed in Python)
The group appears to be experienced in creating malware and is paying considerable attention to the EnemyBot botnet, constantly adding exploits for new vulnerabilities as they emerge and often before system administrators have time to implement fixes.
See also: Intuit warns QuickBooks customers that they are being targeted in phishing attacks
According to AT&T, someone, likely closely associated with Keksec, released the EnemyBot source code, making it available to any cybercriminal.
Protection
To stay safe, you should promptly update your systems to fix vulnerabilities and security. It is also important to monitor network traffic, including outbound connections.
Currently, EnemyBot's main purpose is DDoS attacks, but it also has the potential for other attacks (e.g. cryptomining, system access, etc.), so it is definitely a big threat.
Further details about the botnet and its new capabilities can be found in the AT&T Alien Labs.
Source: www.bleepingcomputer.com
