PumaBot Botnet: SSH Brute Force Attacks & Device Breaches
- A newly discovered Go-based Linux botnet,dubbed PumaBot,is actively brute-forcing SSH credentials on embedded IoT devices to deploy malicious payloads.This IoT botnet exhibits targeted behavior, focusing on specific IP...
- darktrace researchers detailed PumaBot's attack flow, indicators of compromise, and detection rules in a recent report.
- During the brute-force process, PumaBot checks for a "Pumatronix" string, which suggests a focus on surveillance and traffic camera systems from a specific vendor.
PumaBot, a dangerous new Go-based Linux botnet, aggressively targets vulnerable IoT devices, especially surveillance cameras, with SSH brute-force attacks. This IoT botnet prioritizes specific IP addresses to deploy malicious payloads, potentially aiming for deeper network infiltration and data breaches. Researchers have detailed PumaBot’s attack flow,revealing how it exploits weak SSH credentials to gain access. Once inside, PumaBot executes commands to exfiltrate data, install additional malware, and facilitate lateral movement. News Directory 3 reports that teh botnet injects its own SSH key for persistent access, making removal challenging. Infected devices are then used for data theft. Mitigating this threat requires updated firmware, strong passwords, and network segmentation. Discover what’s next in the realm of evolving cyber threats.
PumaBot IoT Botnet targets Surveillance Cams with SSH Brute-Force
Updated May 28,2025
A newly discovered Go-based Linux botnet,dubbed PumaBot,is actively brute-forcing SSH credentials on embedded IoT devices to deploy malicious payloads.This IoT botnet exhibits targeted behavior, focusing on specific IP addresses obtained from a command-and-control (C2) server rather than conducting broad internet scans.
darktrace researchers detailed PumaBot’s attack flow, indicators of compromise, and detection rules in a recent report. The malware receives a list of target IPs from its C2 server and attempts brute-force login attempts on port 22, seeking open SSH access.
During the brute-force process, PumaBot checks for a “Pumatronix” string, which suggests a focus on surveillance and traffic camera systems from a specific vendor. Once targets are identified, the malware receives credentials to test against them.
Upon accomplished login, PumaBot executes ‘uname -a’ to gather environment details and verify the targeted device is not a honeypot. It then writes its main binary (jierui) to /lib/redis and installs a systemd service (redis.service) to ensure persistence across device reboots. To maintain access even after cleanup attempts,PumaBot injects its own SSH key into the ‘authorized_keys’ file.
With an active infection,PumaBot can receive commands to exfiltrate data,introduce new payloads,or steal information to facilitate lateral movement within a network. Darktrace observed example payloads including self-updating scripts, PAM rootkits replacing the legitimate ‘pam_unix.so’, and daemons (binary file “1”).

Source: Darktrace
The malicious PAM module harvests local and remote SSH login details, storing them in a text file (con.txt). A “watcher” binary (1) constantly monitors for this file and exfiltrates it to the C2 server. After exfiltration, the text file is wiped from the infected host to remove traces of the malicious activity.
the full scope and success rate of this PumaBot IoT botnet remain unknown, as Darktrace has not disclosed the size of the target IP lists. Though,its targeted approach suggests a shift towards deeper corporate network infiltration,rather than using infected IoT devices for less sophisticated cybercrimes like distributed denial of service (DDoS) attacks or proxying networks.
What’s next
To defend against botnet threats like PumaBot, security experts recommend upgrading IoT devices to the latest firmware, changing default credentials, deploying firewalls, and isolating IoT devices on separate networks from critical systems.
