A new Mirai variant is attacking Linux devices to build a beastly DDoS botnet

DDoS attack
(Image credit: FrameStockFootages / Shutterstock)

Researchers from Palo Alto Networks’ Unit 42 have spotted a new variant of the infamous Mirai botnet, spreading to Linux-based servers and IoT devices in order to create an enormous swarm of DDoS grunts.

In order to infect the endpoints with the new V3G4 botnet, the attackers would brute-force weak, or default telnet/SSH credentials, and then abuse one of the 13 known vulnerabilities to remotely execute code and install the malware

So far, between July 2022 and December 2022, the researchers spotted three different campaigns, all of which seem to originate from the same threat actor. The reasoning here is that the hardcoded C2 domains contain the same string in all three, the shell script downloads are similar, and the botnet clients are all reportedly similar in features.

Fighting against other botnets

The botnet comes with a number of interesting features, including one in which it tries to terminate, among other processes, those belonging to other botnet families. So, it’s safe to assume that the threat actors are trying to hijack already compromised endpoints from other threat actors. 

Furthermore, unlike other Mirai variants which use just one XOR encryption key, V3G4 uses four, making it harder for cybersecurity researchers to reverse-engineer the malware.

The best way to protect against V3G4 is to make sure your Linux-powered endpoints are up-to-date and invulnerable not just to the 13 flaws being abused in these campaigns, but also any other flaws known to the wider cybercriminal community.

Besides patching, having a strong firewall, as well as a cybersecurity solution, will help defend against any malware deployment attempts. 

Linux devices, as widespread as they are, are a popular target for threat actors looking to create and expand a botnet. Everything from routers, to home cameras, to smart home devices, can be used as a bot and deployed in distributed denial of service attacks.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Industrial routers are being hit by zero-days from new Mirai botnets
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
TP-Link and NR routers targeted by worrying new botnet
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Dangerous new botnet targets webcams, routers across the world
DDoS attack
Juniper Networks warns Mirai botnet is back and targeting new devices
DDoS Attack
Watch out, your office phone could be hijacked into a Mirai botnet
A display showing off the Google TV homepage, with icons for 1917, Scoob!, YouTube and Twitch (among others)
This dangerous malware botnet now covers 1.6 million Android TVs - find out if you're at risk
Latest in Security
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Latest in News
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
The logo of the social media app Bluesky is seen on the screen of a mobile phone
Bluesky gets a massive video upgrade to tempt X fans who are frustrated by its cyberattack outages
Acer Aspire 14 AI laptop display showing the Windows 11 login screen
Shock, horror – I’m not going to argue with Microsoft’s latest bit of nagging in Windows 11, as this pop-up is justified
Europe
Apple and Meta set to face fines for alleged breaches of EU DMA
Garmin Forerunner 965 on wrist in the dark
New Garmin leak suggests a release is days away, but don't get your hopes up for the Forerunner 975
Xbox Series X
Xbox is reportedly teaming up with a mystery manufacturer to launch a PC gaming handheld this year