logo

Active Shellshock SMTP Botnet Campaign

ID: 5d8064e5-ac17-579c-9779-8b88d0c444c6

STIX ID: report--5d8064e5-ac17-579c-9779-8b88d0c444c6

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-09-21

Date Updated: 2026-04-27

...
...

An active campaign is exploiting the Shellshock bash vulnerability by placing exploit payloads in email header fields (subject, body, to/from) to cause SMTP gateways to download a Perl-based botnet (from a malicious site) and join an IRC-controlled botnet; organizations are advised to patch Bash immediately and monitor/block such activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.