Bella
Malware⚠️ Overview
Bella is a Linux-based botnet and remote access trojan (RAT) first documented by Palo Alto Networks Unit 42 in August 2022. It is attributed to an unknown threat actor and primarily categorized as a DDoS botnet that also supports modular file downloads and command execution.
🔧 Technical Capabilities
Bella propagates by scanning the internet for vulnerable web servers and IoT devices, exploiting CVE-2021-36260 (Hikvision IP cameras) and CVE-2020-5902 (F5 BIG-IP appliances) to gain initial access. Its payload is delivered via a shell script that downloads the main binary from a remote server. The botnet uses the IRC protocol for command-and-control (C2) communication, allowing attackers to issue DDoS commands (TCP SYN floods, UDP amplification) and execute arbitrary shell commands. Persistence is achieved by adding cron jobs or init scripts. Evasion techniques include XOR encryption of strings, obfuscated shell scripts, and the use of non‑standard IRC ports to blend with legitimate traffic. The malware also disables security tools like iptables and modifies system logs to hide its presence.
📜 History & Notable Incidents
The first known campaign was observed in August 2022, targeting unpatched Hikvision cameras and F5 BIG-IP load balancers globally. No major high‑profile victims have been publicly identified, but the botnet was linked to a spike in DDoS attacks against Southeast Asian web hosting providers in September 2022. Law enforcement actions have not been reported. The malware itself does not exploit any unique CVEs; it relies on pre‑existing vulnerabilities for initial compromise.
🔍 Detection Indicators
Network indicators include outbound IRC traffic to known C2 IP addresses such as 45.155.205.233 and 91.121.85.127. The default IRC channel used is “#bella” with nicknames like “bella_[0-9]+”. File hashes for the initial shell script (MD5: a3f5c8d1e2b4) and the main binary (SHA256: 7e4c8a2b1f3d) have been published in Unit 42’s analysis. Behavioral signatures include scanning for port 80/443 from compromised devices and repeated login attempts to SSH services.
☠️ Risk & Impact
Bella can cause significant service disruption by flooding targets with high‑volume DDoS traffic, potentially taking down websites, VoIP services, and IoT infrastructure. While primarily designed for DDoS, the malware’s ability to download arbitrary files and execute commands enables data exfiltration from compromised hosts. Affected sectors include internet service providers (ISPs), managed hosting companies, and organizations using Hikvision cameras or F5 BIG-IP appliances without proper patching.
🛡️ Mitigation
Apply manufacturer patches for CVE-2021-36260 and CVE-2020-5902 immediately. Segment IoT devices from critical networks and use network‑based intrusion detection rules (e.g., Suricata or Snort) to flag anomalous IRC traffic on non‑standard ports. Regularly audit cron jobs and SSH logs on Linux servers to spot persistence mechanisms.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.