Analyzing a Go-Based IoT Self-Propagating DDoS Botnet
Akamai Technologies, Thursday, September 3rd, 2026
Akamai researchers dissect a Go-written IoT botnet that self-propagates by scanning IPv4 for exposed routers and Langflow servers.
Akamai's Security Intelligence Response Team analyzed a self-propagating IoT botnet written in Go that pairs automated device scanning with remote command-and-control.
The malware compromises devices by exploiting router vulnerabilities and Langflow CVE-2026-33017, then recruits them into a DDoS platform offering roughly 30 attack methods spanning volumetric floods, packet-rate techniques and game-server-specific attacks.
Propagation relies on blind random IPv4 scanning for exposed router configuration interfaces rather than a predetermined target list. Because the scanner grows the fleet autonomously while operators retain centralized control, the botnet can keep expanding and vary its traffic patterns to evade detection.