PumaBot Targets Linux Devices in Latest Botnet Campaign
ID: fe983ff0-aa1c-5c47-af6a-fbcfbb77b3d6
STIX ID: report--fe983ff0-aa1c-5c47-af6a-fbcfbb77b3d6
Feed Name: Dark Reading
Date Published: 2025-05-29
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
PumaBot is a novel Go-based Linux botnet observed targeting IoT devices by retrieving target lists and credentials from a C2, then brute-forcing SSH rather than scanning the Internet. After gaining access it establishes persistence (writing to /lib/redis, adding SSH keys), fingerprints environments to avoid honeypots, exfiltrates system details in JSON to its C2, and is linked to a broader campaign including a Go backdoor, an SSH brute-forcer that self-updates, and a PAM rootkit used to steal credentials; researchers recommend monitoring SSH activity, auditing systemd services and authorized_keys, and alerting on suspicious outbound HTTP headers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
