APT / THREAT GROUP

ZeroBot

3
aliases
Last seen:Mar 17, 2026

Intelligence Profile

ZeroBot is a Go-based botnet that spreads primarily through IoT and web application vulnerabilities. It is offered as malware as a service (MaaS) and infrastructure overlaps with DDoS-for-hire services seized by the FBI in December 2022.

Threat Analysis

ZeroBot is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

External References

Quick Facts

TypeAPT / Threat Group
Aliases3

Also Known As

ZeroBotZeroStresserelf.zerobot

External Intelligence

Malpedia: elf.zerobot

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.
ZeroBot — APT / Threat Group | Threat Intelligence | CTIWATCH.COM