Articles tagged "Botnet"

Found 95 articles

Critical
The DDoS Botnet With A Consent Dialog

Cyber Defense Magazine

Actively Exploited

A new type of DDoS botnet has emerged, using smart TVs as unwitting participants. These devices, which are often left on standby and connected to the internet, can be manipulated to launch Distributed Denial of Service (DDoS) attacks without the owner's knowledge. Researchers highlighted that these TVs are particularly vulnerable because they are rarely monitored or updated, making them ideal targets for attackers. This situation raises concerns about the security of Internet of Things (IoT) devices, as they can be exploited to create a large network of compromised devices that can overwhelm online services. Users and manufacturers need to take action to secure these devices and prevent them from being used in cyberattacks.

Read Original

A group known for operating a click-fraud botnet is now targeting infotainment systems in vehicles, exploiting legitimate update mechanisms to spread malware. This new tactic allows attackers to hijack the update process, potentially infecting car head units with malicious software. The implications of this are concerning, as it could compromise the functionality of car systems and expose personal data of drivers and passengers. This type of attack not only puts individuals at risk but also raises questions about the security of automotive software updates. Users of affected vehicle infotainment systems should remain vigilant and consider how they manage software updates to protect against these threats.

Read Original

Kaspersky researchers have identified a new type of malware specifically designed for car head units, which are the infotainment systems found in vehicles. This malware has been linked to the BadBox botnet, a network that has already compromised millions of devices. The malware's targeting of car systems raises significant concerns about the security of vehicle technology, as it could potentially allow attackers to control various functions of the car or access sensitive data. This incident emphasizes the growing vulnerability of modern vehicles to cyber threats, highlighting a need for stronger security measures in automotive technology. Car manufacturers and users alike should be aware of this emerging threat and take precautions to safeguard their systems.

Read Original

Several notable cybersecurity incidents have emerged recently. The Threema messaging platform experienced a distributed denial-of-service (DDoS) attack, disrupting its services and potentially affecting user communications. In another development, the Evooo1Bot Linux botnet has been identified, which may pose risks to Linux-based systems by allowing attackers to execute commands remotely. Additionally, Crypto4A has achieved a significant milestone by securing top-tier certification from NIST, highlighting its commitment to cybersecurity standards. These incidents illustrate ongoing challenges in the digital landscape and the constant need for vigilance among users and organizations alike.

Read Original

The Evooo1Bot is a new Linux botnet that significantly enhances the capabilities of the existing Mirai botnet. Researchers found that Evooo1Bot is not just focused on launching DDoS attacks; it also includes modules for exploiting vulnerabilities, stealing credentials, and creating reverse SOCKS relays. This means that compromised devices can be used for more than just overwhelming targets with traffic; they can serve as a persistent infrastructure for attackers. The expansion of these capabilities poses a serious risk to users and organizations, as it increases the potential for data theft and ongoing exploitation. Security professionals need to be vigilant about the devices on their networks to prevent becoming part of this botnet.

Read Original

Researchers have discovered a new Linux botnet called Evooo1Bot, which builds upon the Mirai botnet's source code. This botnet can exploit known vulnerabilities to convert internet-facing devices into SOCKS5 proxies. The malware not only incorporates the DDoS capabilities of Mirai but also adds several new features that enhance its functionality. This poses a significant risk as it can affect various edge devices that are often less secure and can be used for malicious activities like distributed denial-of-service attacks. Users and companies with exposed devices need to take immediate action to protect their systems from this emerging threat.

Read Original
Actively Exploited

The latest edition of the Security Affairs Malware newsletter features significant developments in malware tactics, particularly focusing on the Kimsuky group. Researchers report that Kimsuky has integrated artificial intelligence into its operations, employing AI-generated decoy documents to mislead targets and utilizing a local language model for enhanced attack capabilities. Additionally, the newsletter discusses the evolution of the Kimwolf botnet, now at version 7, which poses a growing risk to various organizations. Agencies like CISA and the FBI are urging companies to stay vigilant against these emerging threats. The evolution of these malware tactics underscores the need for organizations to bolster their cybersecurity measures to protect sensitive information.

Read Original

A new botnet named Evooo1Bot has emerged, targeting internet-facing routers and other gateway devices. Based on the Mirai malware, this botnet converts these devices into SOCKS5 traffic relay nodes, allowing attackers to route internet traffic through them. This can enable various types of malicious activities, including distributed denial-of-service (DDoS) attacks. The attack affects any vulnerable Linux-based routers or similar devices that are exposed to the internet, making it crucial for users and network administrators to secure their devices against unauthorized access. As the botnet continues to spread, it poses a significant risk to network integrity and privacy.

Read Original

A new botnet called Evooo1Bot has emerged, built on the Mirai framework and featuring enhanced capabilities. This botnet is designed to convert compromised edge devices into persistent proxies, which can be exploited for various malicious activities. Researchers have noted that this could significantly impact Internet of Things (IoT) devices, making them potential tools for cybercriminals. The ability to create proxies means that attackers can mask their identity and amplify their operations, raising concerns about privacy and security. Users of affected devices need to be vigilant and improve their security measures to prevent being turned into unwitting participants in these attacks.

Read Original

The Kimwolf botnet has been revamped following police actions that previously dismantled it, including server seizures and the arrest of an alleged operator. Researchers indicate that the botnet now employs tactics to disguise its attacks as normal Chrome web traffic, complicating detection efforts. Additionally, it retrieves commands from the Ethereum blockchain, enhancing its resilience against future takedowns. This evolution poses a significant challenge for cybersecurity experts as it becomes harder to trace and mitigate. The resurgence of Kimwolf highlights ongoing vulnerabilities in network security and the persistent threat posed by sophisticated botnets.

Read Original

Researchers from Palo Alto Networks Unit 42 have identified a new version of the Kimwolf botnet, known as Kimwolf v7, which targets Android devices and Internet of Things (IoT) devices. This upgraded botnet enhances its ability to launch distributed denial-of-service (DDoS) attacks by disguising its HTTP/2 traffic to resemble legitimate web browsing. This makes it harder for security systems to detect and mitigate the attacks. The discovery of Kimwolf v7 raises concerns for users of vulnerable Android and IoT devices, as attackers can exploit these weaknesses to disrupt services and potentially gain unauthorized access to sensitive information. Companies and users need to be vigilant and ensure their devices are secured against such threats.

Read Original

Researchers have discovered the Dysphoria botnet, which has compromised around 200,000 devices globally. This botnet is particularly notable because it uses Ethereum and Solana blockchain domains to obscure its command and control (C2) infrastructure, making it harder to track and shut down. The botnet is an evolution of previous malware known as jackskid and fbot. The collaboration between QiAnXin XLab and China’s CNCERT to reveal this threat underscores the ongoing challenges in combating sophisticated cybercriminal operations. The use of blockchain technology for such malicious purposes raises concerns about the security of connected devices and the methods attackers are using to evade detection.

Read Original

A new botnet called Tengu, derived from the well-known Mirai botnet, has been identified targeting compromised Linux devices. Researchers from Nozomi Networks Labs found that Tengu can utilize a device's hardware watchdog feature to reboot itself whenever defenders attempt to terminate its main process. This persistence method allows Tengu to re-establish its operation even after being interrupted. The botnet primarily gains access through brute-force attacks on Telnet credentials. Tengu is capable of launching distributed denial-of-service (DDoS) attacks, which can overwhelm targeted systems and disrupt online services. This incident raises concerns for organizations relying on Linux devices, as Tengu's ability to persist poses a significant challenge for cybersecurity defenses.

Read Original
Actively Exploited

A new botnet named Dysphoria has taken control of approximately 200,000 devices globally. This botnet is primarily being used to conduct distributed denial of service (DDoS) attacks and to relay traffic, which can disrupt services and overwhelm targeted networks. The widespread nature of Dysphoria means that it could potentially affect various sectors, making it a significant concern for cybersecurity experts. Users with compromised devices may experience slower internet speeds or disruptions in service, while organizations could face costly downtime and reputational damage. The rapid spread of this botnet underscores the ongoing challenges in securing Internet of Things (IoT) devices and emphasizes the need for improved security practices among users and manufacturers alike.

Read Original

The Dysphoria botnet, which targets Internet of Things (IoT) devices, has evolved its infrastructure by incorporating blockchain-based name services and victim relays. This change comes after a law enforcement operation in March disrupted the JackSkid botnet, which had been a significant player in the IoT threat landscape. Researchers from CNCERT and XLab report that these new features make Dysphoria more resilient against future disruptions. By using blockchain technology, the botnet can better obscure its command and control functions, making it harder for authorities to shut it down. This development raises concerns for users of IoT devices, as it indicates an increase in the sophistication of attacks on interconnected devices.

Read Original
Page 1 of 7Next