216.73.216.6

PumaBot: Novel Botnet Targeting IoT Surveillance Devices

· Published 04/06/2025 20:39 · Modified 05/06/2025 01:16

Export JSON

Essential information

Published
04/06/2025 20:39
Modified
05/06/2025 01:16
Tags
2025-06-04 botnet credential-theft iot linux persistence pumabot ssh brute-force surveillance
Related entities
1 observables, 8 techniques (mitre), 1 others

Description

A new Go-based named has been identified targeting devices, particularly systems. It brute-forces SSH credentials using lists from a C2 server, then deploys itself and establishes . The malware disguises itself as legitimate system files, creates systemd services, and adds SSH keys for backdoor access. It also includes components for credential theft and system monitoring. The demonstrates sophisticated evasion techniques and aims for long-term access to compromised devices.

External references