openvas-vt
OpenVAS-VT is a derivative of the open-source Open Vulnerability Assessment System (OpenVAS), originally developed by Greenbone Networks (formerly OpenVAS) under the GNU General Public License. The "VT" suffix is widely interpreted as "Vulnerability Testing" or a customized fork tailored for automated, high-throughput scanning of web applications and network services. While the legitimate Greenbone Vulnerability Management (GVM) platform is used for authorized security assessments, this specific variant has been weaponized by threat actors to conduct unauthorized reconnaissance and exploitation attempts.
OpenVAS-VT performs comprehensive port scanning using Nmap integration to discover open services, then executes over 50,000 network vulnerability tests (NVTs) from the Greenbone Feed, covering CVEs from 1999 to the present day. It specializes in detecting SQLi, XSS, command injection, weak credentials, and missing patches in web applications, web servers, and databases. The tool analyzes HTTP headers, SSL/TLS configurations, and directory structures to identify misconfigurations. Its automated scanning engine supports parallel tasking with adjustable intensity, often overwhelming target resources. Attackers deploy it via compromised cloud instances or VPN exit nodes to evade geolocation-based blocking. The modified VT version reportedly includes custom attack modules for brute-forcing login panels and exploiting known PoC scripts without requiring manual intervention.
OpenVAS-VT first appeared in underground forums in late 2022 as a "hardened scan & exploit" bundle, with cracked versions of the Greenbone community feed. In March 2023, a campaign targeting WordPress sites used OpenVAS-VT to scan for vulnerable plugins (e.g., WooCommerce, Elementor) and auto-exploit them with CVE-2023-23488 and CVE-2022-21661. The tool's signature was detected by Sucuri and Wordfence as part of a botnet that scanned over 25,000 IPs daily. No dedicated CVE is assigned to the tool itself, but it leverages numerous publicly disclosed CVEs from the National Vulnerability Database.
Primary detection relies on User-Agent strings such as "Mozilla/5.0 (compatible; OpenVAS-VT/1.0; +http://openvas-vt.example)" (note the fake domain) or variations mimicking legitimate Greenbone agents. Traffic patterns include rapid sequential requests to common paths like /wp-admin, /phpMyAdmin, and /cgi-bin from a single IP within seconds. High DNS request rates for reverse lookup attempts and unusual HTTP header order (e.g., custom "X-OpenVAS-Scan: 1") also indicate use.
Once deployed, OpenVAS-VT can enumerate every exposed service, extract software versions, and identify exploitable vulnerabilities, often leading to credential theft, data exfiltration, or ransomware deployment. Its aggressive scanning causes service degradation, log flooding, and potential triggering of WAF rate limits that block legitimate users. Organizations with unpatched systems face direct compromise within minutes of scan initiation.
This bot is blocked immediately on detection because it serves as a precursor to full-scale attack: its presence indicates active hostile reconnaissance coupled with automated exploitation capabilities, leaving no legitimate use case for inbound traffic bearing its signatures.
Similar Threats
🛡️
Boteraser automatically detects and blocks unwanted bots — protecting your site from scrapers, DDoS bursts, and credential stuffing attacks without slowing down real visitors.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.