morfeus

Bot User-Agent: morfeus

⚠️ Overview

The Morfeus botnet is a malicious, self-propagating malware family first identified in June 2019 by Palo Alto Networks' Unit 42 and subsequently analyzed by Fortinet and Trend Micro. It is operated by a threat actor group believed to be based in Eastern Europe, targeting Linux-based servers and IoT devices for large-scale DDoS attacks, cryptocurrency mining, and credential theft.

🔧 Technical Capabilities

The botnet propagates via brute-forcing SSH credentials and exploiting known vulnerabilities, including CVE-2019-15107 (Webmin remote code execution) and CVE-2019-2725 (Oracle WebLogic deserialization), as documented in the National Vulnerability Database. Once inside a system, it downloads a payload from a remote C2 server using custom XOR encryption for communication. The malware features a modular architecture capable of launching DDoS attacks (HTTP flood, SYN flood, UDP flood), executing arbitrary shell commands, and stealing sensitive data like credentials and configuration files. It also includes a self-propagation module that scans for additional vulnerable hosts on internal networks and over the internet, using a worm-like spread mechanism. Additionally, it deploys the XMRig miner for Monero cryptocurrency, consuming system resources.

📜 History & Notable Incidents

In July 2019, Morfeus was observed infecting over 10,000 devices within a few weeks, primarily targeting unpatched Linux servers and routers. A major incident involved the compromise of a large European hosting provider, leading to a massive DDoS attack that disrupted services for hours. According to a Cybereason report, the botnet's source code was later partially leaked on a hacking forum, spawning multiple variants. The botnet has been linked to attacks against educational institutions and small businesses, with some variants adding ransomware capabilities.

🔍 Detection Indicators

Infected devices exhibit outbound connections to known Morfeus C2 domains (e.g., morfeus[.]com, cmd.morfeus[.]net) on ports 80 and 443. Network traffic shows repeated SSH login attempts from random IPs, and HTTP requests containing unique User-Agent strings such as "Morfeus/1.0" or "Mozilla/5.0 (X11; Linux x86_64) Morfeus". Behavioral fingerprints include high CPU usage from mining processes, periodic beaconing every 60 seconds, and unusual outbound port scanning on ports 22, 80, and 8080.

☠️ Risk & Impact

Successful infection grants full remote control, enabling data exfiltration (SSH keys, database credentials), resource hijacking for cryptocurrency mining, and launching DDoS attacks that saturate network bandwidth. The botnet has been implicated in credential theft from compromised servers, potentially exposing customer databases and administrative access, leading to further lateral movement within organizations.

🛡️ Mitigation

Due to its aggressive propagation using multiple exploitation methods and persistent C2 communication, Morfeus is blocked immediately upon detection to prevent lateral movement, resource abuse, and further compromise of network assets.

Free Bot Analysis

Is Your Site Under Bot Attack Right Now?

Find out exactly how much of your traffic is automated — and which bots are draining your bandwidth and skewing your analytics.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.