s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.pumabot

📛 Threat Title

Malware family: PumaBot

Category: PumaBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.pumabot`. Printable name: PumaBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.pumabot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pumabot

IOC database

Type
domain
Value
elf.pumabot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.pumabot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pumabot

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    A new Go-based Linux botnet named PumaBot has been identified targeting IoT devices, particularly surveillance systems. It brute-forces SSH credentials using lists from a C2 server, then deploys itself and establishes persistence. The malware disguises itself as legitimate system files, creates systemd services, and adds SSH keys for backdoor ...

  • web:blog.polyswarm.io

    PumaBot , a Go-based Linux botnet, targets embedded IoT devices by brute-forcing SSH credentials, establishing persistence, and executing cryptocurrency mining.

  • web:cirt.gy

    Description A newly identified Go-based Linux malware , dubbed PumaBot , is targeting Internet of Things (IoT) devices through SSH brute force attacks to gain unauthorized access and establish persistence. First reported by Darktrace on May 28, 2025, PumaBot is not a typical scattergun botnet.

  • web:cybersecuritynews.com

    A sophisticated new malware strain dubbed PumaBot has emerged in the cybersecurity landscape, specifically targeting Internet of Things (IoT) devices through aggressive SSH credential brute-forcing campaigns. This latest threat represents a significant evolution in IoT-focused malware , demonstrating advanced persistence mechanisms and stealth capabilities that allow it to maintain long-term ...

  • web:imtr.net

    # Tool/Technique: PumaBot ## Overview PumaBot is described as a novel botnet specifically targeting Internet of Things (IoT) surveillance devices. Its purpose is likely to compromise these devices for inclusion in a larger botnet infrastructure, potentially for large-scale attacks like DDoS.

  • web:securityaffairs.com

    PumaBot targets Linux IoT devices, using SSH brute-force attacks to steal credentials, spread malware , and mine crypto.

  • web:thehackernews.com

    Embedded Linux-based Internet of Things (IoT) devices have become the target of a new botnet dubbed PumaBot . Written in Go, the botnet is designed to conduct brute-force attacks against SSH instances to expand in size and scale and deliver additional malware to the infected hosts.

  • web:www.darktrace.com

    Introduction: PumaBot attacking IoT devices Darktrace researchers have identified a custom Go-based Linux botnet named " PumaBot " targeting embedded Linux Internet of Things (IoT) devices. Rather than scanning the Internet, the malware retrieves a list of targets from a command-and-control (C2) server and attempts to brute-force SSH credentials. Upon gaining access, it receives remote ...

  • web:www.pcrisk.com

    The infection of IoT surveillance devices by PumaBot poses several risks to enterprises that are compromised by the malware . This includes infected devices used in DDoS attacks to flood targeted systems with traffic, causing service disruptions.

  • web:www.prsol.cc

    A newly discovered Go-based Linux botnet malware named PumaBot is brute-forcing SSH credentials on embedded IoT devices to deploy malicious payloads. The targeted nature of PumaBot is also evident by the fact it targets specific IPs based on lists pulled from a command-and-control (C2) server instead of broader scanning of the internet.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.