This dangerous botnet has found a new way to infect your endpoints

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • PCHF IT Feeds
    PCHF Bot
    • Jan 2015
    • 54573

    #1

    This dangerous botnet has found a new way to infect your endpoints

    A dangerous new botnet is adding new ways to infect vulnerable endpoints almost every day, researchers are saying.

    Multiple cybersecurity research teams spotted a botnet called EnemyBot in March this year, and at first, it was found to be abusing critical vulnerabilities in web servers, CMS platforms, Android smartphones and Internet of Things (IoT) devices.

    Since then, researchers have been tracking the development of the botnet and have found its creators are fast adding newly discovered vulnerabilities to the list of attack vectors.

    The latest report, coming from AT&T Alien Labs, says 24 new vulnerabilities have been added, including some that don’t even have a CVE number yet, making them extremely dangerous.


    https://cdn.mos.cms.futurecdn.net/ybbmQ8p4Q999AkMWkW8HLm.jpg


    Share your thoughts on Cybersecurity and get a free copy of the Hacker’s Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

    [HEADING=1]DDoS attacks[/HEADING]

    Among the flaws, as noted by BleepingComoputer, are multiple critical vulnerabilities in VMware Workspace ONE access and VMware Identity Manager, as well as F5 BIG-IP.

    While the botnet’s main goal is to run Distributed Denial of Service (DDoS) attacks, it also allows operators to create a reverse shell on the target device, bypassing firewalls and other defense mechanisms.

    Read more
    This rapidly expanding botnet is launching DDoS attacks left, right and center

    A new botnet is launching attacks on millions of routers and IoT devices

    Linux botnet abuses log4j to attack Arm, x86-based devices
    The group behind EnemyBot seems to be Keksec, a threat actor also known as Necro, & Freakout. It is most famous for operating the Tsunami DDoS malware dubbed “Ryuk” (not to be confused with the malware of the same name).

    According to Bleeping Computer, this seems to be an experienced group, which recently seems to have published the botnet’s source code.

    To protect from a DDoS attack, organizations are advised to patch their operating systems and software as soon as possible, install a firewall and monitor network traffic, and make sure all devices are protected by an antivirus service.

    [ul]
    [li]Shield against one of the most common threats around with the best ransomware protection[/li][/ul]

    Via BleepingComputer

    Continue reading…
Working...