logo

Malware Analysis of the DreamBus Botnet

ID: 29a44f8b-bfba-5145-8e14-30f863df4425

STIX ID: report--29a44f8b-bfba-5145-8e14-30f863df4425

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zscaler ThreatLabZ analyzed DreamBus, a modular, worm-like Linux botnet (SystemdMiner variant) that spreads via SSH brute-force, weak credentials, and multiple unauthenticated RCE exploits (PostgreSQL, Redis, Hadoop YARN, Apache Spark, Consul, SaltStack). The report provides in-depth TTPs, IOCs (hashes, domains, IPs, filenames), detection signatures (YARA/Snort), and notes current monetization via XMRig Monero mining while warning the actor could pivot to more destructive activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.