{"id":46220,"date":"2022-04-13T14:47:29","date_gmt":"2022-04-13T14:47:29","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/33323\/Enemybot-A-New-Mirai-Gafgyt-Hybrid-Botnet-Joins-The-Scene.html"},"modified":"2022-04-13T14:47:29","modified_gmt":"2022-04-13T14:47:29","slug":"enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/","title":{"rendered":"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\/2021\/08\/02\/9500e900-070f-49e2-b214-e088fa9e3f9b\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\" class=\"ff-og-image-inserted\"><\/div>\n<p>A new botnet is targeting routers, Internet of Things (IoT) devices, and an array of server architectures.<\/p>\n<p>On April 12, cybersecurity researchers from FortiGuard Labs said the new distributed denial-of-service (DDoS) botnet, <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/enemybot-a-look-into-keksecs-latest-ddos-botnet\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">dubbed Enemybot<\/a>, borrows modules from the infamous Mirai botnet&#8217;s source code, alongside Gafgyt&#8217;s.<\/p>\n<p>The Mirai botnet was responsible for a massive DDoS attack against <a href=\"https:\/\/www.zdnet.com\/article\/source-code-of-mirai-botnet-responsible-for-krebs-on-security-ddos-released-online\/\" target=\"_blank\" rel=\"noopener\">Dyn in 2016<\/a>. Mirai&#8217;s source code was leaked online in the same year, and even now, botnets utilizing parts of the malicious network continue to be weapons of choice for threat actors. <\/p>\n<p>Gafgyt\/Bashlite code is also public, and according to FortiGuard, the new Enemybot employs elements of both botnets in its attacks, <a href=\"https:\/\/www.zdnet.com\/article\/mirai-splinter-botnets-dominate-iot-attack-scene\/\" target=\"_blank\" rel=\"noopener\">joining the likes of<\/a> Okiru, Satori, and Masuta. <\/p>\n<p>Keksec is thought to be the botnet&#8217;s operator. Keksec, also known as Necro or Freakout, is a prolific threat group connected to DDoS assaults, cyberattacks against cloud service providers, and cryptojacking campaigns. <\/p>\n<p>According <a href=\"https:\/\/www.lacework.com\/blog\/keksec-tsunami-ryuk\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">to Lacework<\/a>, the threat group is also the developer of a Tsunami DDoS malware variant called &#8220;Ryuk,&#8221; although this is not to be confused with the Ryuk ransomware family. <\/p>\n<p>Enemybot was first discovered in March 2022. The botnet uses Mirai&#8217;s scanner module and bot killer, which checks for running processes in memory and terminates any competitors based on a selection of keywords. <\/p>\n<p>The team has described the botnet as an &#8220;updated and &#8220;rebranded&#8221; variant of Gafgyt_tor&#8221; due to its heavy reliance on botnet functions sourced from Gafgyt&#8217;s codebase. <\/p>\n<p>Enemybot will attempt to compromise a wide range of devices and architectures through techniques including brute-force attacks and vulnerability exploitation.<\/p>\n<p>Seowon Intech, D-Link, Netgear, Zhone, and D-Link routers are targeted, as well as iRZ mobile routers and misconfigured Android devices. The threat actors will try to exploit both old, patched vulnerabilities and newer security issues such as <a href=\"https:\/\/www.zdnet.com\/article\/the-log4j-flaw-hasnt-led-to-massive-hacking-attacks-but-that-doesnt-mean-the-threat-is-over\/\" target=\"_blank\" rel=\"noopener\">Log4j<\/a>. <\/p>\n<p>When it comes to architecture, Enemybot isn&#8217;t too picky. Desktop and server systems on arm, arm64, Darwin, and BSD are attacked, alongside many others. <\/p>\n<p>&#8220;This mix of exploits targeting web servers and applications beyond the usual IoT devices, coupled with the wide range of supported architectures, might be a sign of Keksec testing the viability of expanding the botnet beyond low-resource IoT devices for more than just DDoS attacks,&#8221; the researchers say. <\/p>\n<p>Once the malware has compromised a device or server, a text file is loaded with cleartext messages, such as: &#8220;ENEMEYBOT V3.1-ALCAPONE &#8211; hail KEKSEC, ALSO U GOT haCkED MY [REDACTED] (Your device literally has the security of a [shitty device] \/ [smart doorbell]).&#8221; <\/p>\n<p>Enemybot then grabs binaries, depending on the target architecture, and executes a range of DDoS-related commands. <\/p>\n<p>The malware can also use a range of obfuscation methods to hinder analysis and hide its presence. The botnet&#8217;s command-and-control (C2) server is hosted on a .onion domain, only accessible via the Tor network. <\/p>\n<p>Enemybot is still under active development. <\/p>\n<p>&#8220;We expect that more updated versions will be distributed in the wild soon,&#8221; the researchers say. &#8220;FortiGuard Labs will keep monitoring this botnet.&#8221; <\/p>\n<h3> Previous and related coverage <\/h3>\n<hr>\n<p><strong>Have a tip?<\/strong> Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0<\/p>\n<hr>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/33323\/Enemybot-A-New-Mirai-Gafgyt-Hybrid-Botnet-Joins-The-Scene.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[6444],"class_list":["post-46220","post","type-post","status-publish","format-standard","hentry","category-packet-storm","tag-headlinemalwarebotnet"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-13T14:47:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/a\/img\/resize\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\/2021\/08\/02\/9500e900-070f-49e2-b214-e088fa9e3f9b\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene\",\"datePublished\":\"2022-04-13T14:47:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/\"},\"wordCount\":530,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\\\/2021\\\/08\\\/02\\\/9500e900-070f-49e2-b214-e088fa9e3f9b\\\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"keywords\":[\"headline,malware,botnet\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/\",\"name\":\"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\\\/2021\\\/08\\\/02\\\/9500e900-070f-49e2-b214-e088fa9e3f9b\\\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"datePublished\":\"2022-04-13T14:47:29+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\\\/2021\\\/08\\\/02\\\/9500e900-070f-49e2-b214-e088fa9e3f9b\\\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\\\/2021\\\/08\\\/02\\\/9500e900-070f-49e2-b214-e088fa9e3f9b\\\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,malware,botnet\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemalwarebotnet\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/","og_locale":"en_US","og_type":"article","og_title":"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-04-13T14:47:29+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/a\/img\/resize\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\/2021\/08\/02\/9500e900-070f-49e2-b214-e088fa9e3f9b\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene","datePublished":"2022-04-13T14:47:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/"},"wordCount":530,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\/2021\/08\/02\/9500e900-070f-49e2-b214-e088fa9e3f9b\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","keywords":["headline,malware,botnet"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/","url":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/","name":"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\/2021\/08\/02\/9500e900-070f-49e2-b214-e088fa9e3f9b\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","datePublished":"2022-04-13T14:47:29+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/#primaryimage","url":"https:\/\/www.zdnet.com\/a\/img\/resize\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\/2021\/08\/02\/9500e900-070f-49e2-b214-e088fa9e3f9b\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","contentUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/3e9a6eca18bbbab3b21f1952aa1a5f24d4f407c3\/2021\/08\/02\/9500e900-070f-49e2-b214-e088fa9e3f9b\/global-cybersecurity-cyberattack-network-gps.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/enemybot-a-new-mirai-gafgyt-hybrid-botnet-joins-the-scene\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,malware,botnet","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemalwarebotnet\/"},{"@type":"ListItem","position":3,"name":"Enemybot: A New Mirai, Gafgyt Hybrid Botnet Joins The Scene"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/46220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=46220"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/46220\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=46220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=46220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=46220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}