logo

New PumaBot botnet brute forces SSH credentials to breach devices

ID: 3f790a7c-8835-5407-a28b-905f9371a5e5

STIX ID: report--3f790a7c-8835-5407-a28b-905f9371a5e5

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-05-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A newly discovered Go-based botnet named PumaBot targets embedded Linux IoT devices (notably surveillance and traffic cameras) by receiving target IP lists from a C2 and brute-forcing SSH credentials; once access is gained it installs a persistent binary, injects SSH keys, and deploys payloads such as PAM rootkits and exfiltration daemons to harvest and send credentials to the C2. Darktrace documented the malware's infection flow, IoCs, and detection rules; the botnet's scale is unknown but its targeted approach and persistence enable potential lateral movement into deeper networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.