Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
PumaBot Botnet: SSH Brute Force Attacks & Device Breaches - News Directory 3

PumaBot Botnet: SSH Brute Force Attacks & Device Breaches

May 28, 2025 Catherine Williams Tech
News Context
At a glance
  • A newly discovered Go-based Linux botnet,dubbed PumaBot,is actively brute-forcing SSH credentials on embedded IoT devices to deploy‍ malicious payloads.This IoT botnet exhibits targeted behavior, focusing on specific IP...
  • darktrace researchers detailed PumaBot's attack flow, indicators of ‍compromise, and⁣ detection rules in a recent report.
  • During the brute-force process, PumaBot checks for a "Pumatronix" string, which suggests a focus on surveillance and traffic camera systems from a specific⁢ vendor.
Original source: bleepingcomputer.com

PumaBot, ⁣a dangerous new Go-based⁣ Linux botnet, aggressively targets vulnerable IoT devices, especially surveillance cameras, with SSH brute-force⁢ attacks. This IoT botnet prioritizes specific IP addresses to deploy ‍malicious payloads, potentially aiming for deeper network infiltration and data ⁢breaches. Researchers have‍ detailed PumaBot’s attack flow,revealing how it exploits weak SSH credentials to gain access. Once inside, ⁢PumaBot executes commands to exfiltrate data, install additional malware, and facilitate⁣ lateral movement.⁢ News Directory 3 reports that teh botnet⁢ injects its own SSH key for persistent access, making⁢ removal challenging. Infected devices are then used for data theft. Mitigating this threat requires updated firmware, strong passwords,⁢ and network segmentation. Discover what’s⁣ next in the realm of evolving cyber threats.


PumaBot IoT Botnet Targets surveillance Cams with SSH Brute-Force













Key Points

  • PumaBot malware targets IoT devices⁤ via SSH brute-force ⁤attacks.
  • The botnet focuses on specific IPs, perhaps targeting surveillance systems.
  • Infected devices can be used for data exfiltration and lateral movement.

PumaBot IoT Botnet targets Surveillance Cams⁢ with SSH Brute-Force

Updated May 28,2025
‍

A newly discovered Go-based Linux botnet,dubbed PumaBot,is actively brute-forcing SSH credentials on embedded IoT devices to deploy‍ malicious payloads.This IoT botnet exhibits targeted behavior, focusing on specific IP addresses obtained from a⁤ command-and-control‍ (C2) server rather than conducting broad internet scans.

darktrace researchers detailed PumaBot’s attack flow, indicators of ‍compromise, and⁣ detection rules in a recent report. The malware receives a list of target IPs from its C2 server and attempts brute-force login attempts on port ‍22, seeking open SSH access.

During the brute-force process, PumaBot checks for a “Pumatronix” string, which suggests a focus on surveillance and traffic camera systems from a specific⁢ vendor. Once targets are identified, the malware receives credentials to test ⁢against them.

Upon accomplished login, PumaBot executes ‘uname -a’ to gather environment details and verify the targeted device is not ⁣a honeypot. It then⁣ writes‍ its main binary (jierui) to /lib/redis and installs a systemd service (redis.service) to ensure persistence across device ⁣reboots. To maintain access even after cleanup attempts,PumaBot injects its own SSH key into the ‘authorized_keys’ file.

With an active infection,PumaBot can receive commands to exfiltrate data,introduce new payloads,or steal information to facilitate lateral movement within a network. Darktrace observed example payloads including self-updating scripts, ‍PAM rootkits replacing the legitimate ‘pam_unix.so’, and daemons (binary file “1”).

Writing credentials on a text file
Writing credentials on a text file
Source: Darktrace

The malicious PAM module harvests local and remote SSH login details, storing them in a text file (con.txt). A “watcher” binary (1) constantly monitors for this file and exfiltrates it to the C2 server. After exfiltration, the text file is wiped from the infected host to ⁣remove traces of the malicious activity.

the full scope and success rate of‍ this PumaBot IoT botnet remain unknown, as Darktrace has not disclosed the size of the target IP ‍lists. Though,its targeted⁢ approach suggests a shift towards deeper corporate network infiltration,rather than using infected IoT devices for less sophisticated cybercrimes like ⁣distributed denial of service (DDoS) attacks or proxying networks.

What’s next

To defend against botnet threats like PumaBot, ⁣security experts recommend upgrading IoT devices to the latest firmware, changing default credentials, deploying firewalls, and isolating IoT devices on separate networks from critical systems.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

More on this

  • POP4.2 Tool Opens Way to Boot Windows 11 26H2 on AMD Phenom Chips
  • Ethereum Price Update: The Latest Trends and Market Outlook

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com