ENIBot/HuntBot Campaign

    Date: 08/18/2026

    Severity: High

    Summary

    ENIbot (also known as HuntBot) is an actively spreading IoT botnet that self-propagates across the internet and conducts Layer 7 DDoS attacks through its C2 infrastructure. Since March 2026, honeypots have recorded millions of exploitation attempts and 3,505 distinct malware samples linked to the campaign. Researchers have identified 7,504 unique bot IP addresses globally based on campaign activity observed in honeypots. The campaign name comes from scripts dropped by the attackers onto the researchers’ honeypots. ENIbot combines automated exploitation, worm-like lateral movement, and a command-driven attack dispatcher. Since May 2026, the campaign has expanded, with scanning and exploitation traffic continuously shifting across its globally distributed botnet hosts.

    Indicators of Compromise (IOC) List

    IP Address

    216.167.26.154

    192.204.41.160

    176.65.139.99

    176.65.139.7

    176.65.139.11

    176.65.139.69

    176.65.139.59

    52.190.182.226

    20.169.94.182

    172.183.94.160

    135.232.224.163

    135.119.132.147

    40.76.181.212

    135.232.200.66

    20.171.55.49

    52.165.58.34

    64.236.135.131

    Hash

    13336d8e6fcda501cf62955c223ba4745cb46adf58f466ce6fa52f3b9d1dbdd5

    58241aaf2b2b87cc6182a1733b8a9de09bd4aa69e4da4edb5513c3d67342bfd5

    608fdb60d879201961f436f1a248ed986e439a046a5c1eea9206e91724422490

    4f5cd984efdbfef840ee33a029e1b757402348274ab60c4bcf91b4472b829074

    2e10d9e18123e3b29362f230a0b6bd84bdd128b4cb5556805dca73f9a303a945

    d2470d22ec573e029b8b87209dade2c0a3720982903ee49dcf431ab010141bc7

    5605190d87a9b363fc5e2e4dd44d0d00f247a16762204d7a8020ad832d2b566e

    07603bb8358cdd76b89b0ceeec0b5bacd462b4bfb5dcb9643365eedb96f00f57

    d07505297fa575149cf9f2ec1c5e812a1b70b92e18374b8782ffcda4d987ca71

    b0f843c70c121199ee9cba7d00757a3ca10256555d5272587405611fd3de7b0d

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("192.204.41.160","176.65.139.69","52.165.58.34","176.65.139.7","135.232.200.66","216.167.26.154","176.65.139.11","64.236.135.131","135.232.224.163","40.76.181.212","176.65.139.59","135.119.132.147","52.190.182.226","176.65.139.99","20.171.55.49","172.183.94.160","20.169.94.182") or srcipaddress IN ("192.204.41.160","176.65.139.69","52.165.58.34","176.65.139.7","135.232.200.66","216.167.26.154","176.65.139.11","64.236.135.131","135.232.224.163","40.76.181.212","176.65.139.59","135.119.132.147","52.190.182.226","176.65.139.99","20.171.55.49","172.183.94.160","20.169.94.182")

    Detection Query 2 :

    sha256hash IN ("2e10d9e18123e3b29362f230a0b6bd84bdd128b4cb5556805dca73f9a303a945","07603bb8358cdd76b89b0ceeec0b5bacd462b4bfb5dcb9643365eedb96f00f57","d2470d22ec573e029b8b87209dade2c0a3720982903ee49dcf431ab010141bc7","d07505297fa575149cf9f2ec1c5e812a1b70b92e18374b8782ffcda4d987ca71","5605190d87a9b363fc5e2e4dd44d0d00f247a16762204d7a8020ad832d2b566e","b0f843c70c121199ee9cba7d00757a3ca10256555d5272587405611fd3de7b0d","13336d8e6fcda501cf62955c223ba4745cb46adf58f466ce6fa52f3b9d1dbdd5","58241aaf2b2b87cc6182a1733b8a9de09bd4aa69e4da4edb5513c3d67342bfd5","608fdb60d879201961f436f1a248ed986e439a046a5c1eea9206e91724422490","4f5cd984efdbfef840ee33a029e1b757402348274ab60c4bcf91b4472b829074")

    Reference:  

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-08-14-ENIBot-HuntBot-Campaign.txt                                   


    Tags

    MalwareBotnetDDoS AttacksExploit

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags