Author: Virus Bulletin - Bewertung: 0x - Views:1
Tracking the IoT botnet's bloodline: code footprints don’t lie
Presented at the VB2025 conference in Berlin, 24 - 26 September 2025.
↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2025/slides/Slides-Tracking-the-IoT-botnets-bloodline-code-footprints-dont-lie.pdf
↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2025/papers/Tracking-the-IoT-botnets-bloodline-code-footprints-dont-lie.pdf
→ Details: https://www.virusbulletin.com/conference/vb2025/abstracts/tracking-iot-botnets-bloodline-code-footprints-dont-lie/
✪ PRESENTED BY ✪
• Chanbin Jeon (SANDS Lab)
• ChangGyun Kim (SANDS Lab)
• SeungBeom Lim (SANDS Lab)
✪ ABSTRACT ✪
In January 2025, we identified a previously unreported IoT bot named "x86", confirmed to be a variant of the Gafgyt (BASHLITE) family, which had infected over one million IoT devices. Upon execution, the bot connects to a command-and-control server in Germany and sends the message "Joined RebirthReborn As". Unlike typical variants, "x86" lacks propagation features and supports only six hard-coded commands, indicating a simplified operational model.
IoT botnet analysis is increasingly difficult due to widespread code reuse and minor modifications by threat actors to evade detection. Manual analysis methods are insufficient to manage the growing number of variants, highlighting the need for automated techniques to track malware lineage and identify relationships between variants.
To meet this challenge, we introduce a hybrid automated analysis framework that combines function-level embedding vector similarity with Large Language Models (LLMs). Decompiled malware functions are transformed into embedding vectors, with similarity measured using cosine and Euclidean distance. This enables efficient clustering, accurate variant detection, and comprehensive malware genealogy tracking.
Using this technique, we analysed the lineage of "x86" and correlated it with contextual intelligence derived from open-source social channels commonly used by threat actors, including YouTube, Discord, Telegram, Instagram and Twitch. Our investigation revealed a clear evolution from the "qBot" variant, progressing through "Demon" and "Rebirth", to the current "Rebirth Reborn".
We named the threat actor group behind this lineage "CTX-5341", comprising actors such as "SelfRepNeTiS". CTX-5341 has operated through cooperative frameworks and reseller models. One member recently launched a standalone DDoS service, "Eternal Stresser", indicating further fragmentation.
Although "SelfRepNeTiS" reportedly exited the scene around 2022 after selling all related source code, the reappearance of Rebirth Reborn in late 2024 suggests renewed activity or third-party operators. Our framework proved highly effective in tracing this lineage. It can also be adapted to other malware families depending on the structure of the analysis dataset, making it a valuable tool for modern malware investigations.