logo

Bashlite Updated with Mining and Backdoor Commands

ID: 2170ba36-5322-5a08-a428-4e50630b6980

STIX ID: report--2170ba36-5322-5a08-a428-4e50630b6980

Feed Name: TrendAI Security Blog

Threat Score
70/100

Date Published: 2026-01-01

Date Updated: 2026-08-06

...
...

Executive summary: The report analyzes a variant of the Bashlite IoT botnet that abuses a Metasploit RCE against WeMo UPnP-enabled devices to deploy a dropper which fetches architecture-specific payloads; the malware provides multiple DDoS flood commands, backdoor functions, cryptocurrency-mining and bricking capabilities, and includes C2 IPs, SHA-256 hashes, and malicious URLs observed in the wild across several countries, with vendor disclosure and mitigation guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.