Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Warren Buffett-Backed Nubank Launches Crypto Trading — Holds Bitcoin on Balance Sheet – Finance Bitcoin News bitcoin news
  • Celsius Hires Citigroup to Help the Startup Find ‘Potential Financing’ – Bitcoin News bitcoin news
  • Warner Bros. and Nifty’s to Launch Looney Tunes Story Bolstered by NFTs – Bitcoin News bitcoin news
  • Atlassian Confluence Flaw Being Used to Deploy Ransomware and Crypto Miners cyber security news
  • Get Lifetime Access to 2022 Cybersecurity Certification Prep Courses @ 95% Off cyber security news
  • Android and Chrome Users Can Soon Generate Virtual Credit Cards to Protect Real Ones cyber security news
  • Researchers Warn of Spam Campaign Targeting Victims with SVCReady Malware cyber security news
  • Bitcoin Turns Bearish, Risk of Drop Below $29K bitcoin news

EnemyBot Linux Botnet Now Exploits Web Server, Android and CMS Vulnerabilities

Posted on May 30, 2022 By root


A nascent Linux-based botnet named Enemybot has expanded its capabilities to include recently disclosed security vulnerabilities in its arsenal to target web servers, Android devices, and content management systems (CMS).

“The malware is rapidly adopting one-day vulnerabilities as part of its exploitation capabilities,” AT&T Alien Labs said in a technical write-up published last week. “Services such as VMware Workspace ONE, Adobe ColdFusion, WordPress, PHP Scriptcase and more are being targeted as well as IoT and Android devices.”

First disclosed by Securonix in March and later by Fortinet, Enemybot has been linked to a threat actor tracked as Keksec (aka Kek Security, Necro, and FreakOut), with early attacks targeting routers from Seowon Intech, D-Link, and iRZ.

CyberSecurity

Enemybot, which is capable of carrying out DDoS attacks, draws its origins from several other botnets like Mirai, Qbot, Zbot, Gafgyt, and LolFMe. An analysis of the latest variant reveals that it’s made up of four different components –

  • A Python module to download dependencies and compile the malware for different OS architectures
  • The core botnet section
  • An obfuscation segment designed to encode and decode the malware’s strings, and
  • A command-and-control functionality to receive attack commands and fetch additional payloads

Also incorporated is a new scanner function that’s engineered to search random IP addresses associated with public-facing assets for potential vulnerabilities, while also taking into account new bugs within days of them being publicly disclosed.

“In case an Android device is connected through USB, or Android emulator running on the machine, EnemyBot will try to infect it by executing [a] shell command,” the researchers said, pointing to a new “adb_infect” function. ADB refers to Android Debug Bridge, a command-line utility used to communicate with an Android device.

Besides the Log4Shell vulnerabilities that came to light in December 2021, this includes recently patched flaws in Razer Sila routers (no CVE), VMware Workspace ONE Access (CVE-2022-22954), and F5 BIG-IP (CVE-2022-1388) as well as weaknesses in WordPress plugins like Video Synchro PDF.

Other weaponized security shortcomings are below –

  • CVE-2022-22947 (CVSS score: 10.0) – A code injection vulnerability in Spring Cloud Gateway
  • CVE-2021-4039 (CVSS score: 9.8) – A command injection vulnerability in the web interface of the Zyxel
  • CVE-2022-25075 (CVSS score: 9.8) – A command injection vulnerability in TOTOLink A3000RU wireless router
  • CVE-2021-36356 (CVSS score: 9.8) – A remote code execution vulnerability in KRAMER VIAware
  • CVE-2021-35064 (CVSS score: 9.8) – A privilege escalation and command execution vulnerability in Kramer VIAWare
  • CVE-2020-7961 (CVSS score: 9.8) – A remote code execution vulnerability in Liferay Portal
CyberSecurity

What’s more, the botnet’s source code has been shared on GitHub, making it widely available to other threat actors. “I assume no responsibility for any damages caused by this program,” the project’s README file reads. “This is posted under Apache license and is also considered art.”

“Keksec’s Enemybot appears to be just starting to spread, however due to the authors’ rapid updates, this botnet has the potential to become a major threat for IoT devices and web servers,” the researchers said.

“This indicates that the Keksec group is well resourced and that the group has developed the malware to take advantage of vulnerabilities before they are patched, thus increasing the speed and scale at which it can spread.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Undervalued Metaverse Project Mars4 Is Preparing for New Releases
Next Post: Frodo Tech Aims to Create Environmentally-Friendly Blockchain Ecosystem That Is Open to Everyone – Sponsored Bitcoin News

Related Posts

  • Web Trackers Caught Intercepting Online Forms Even Before Users Hit Submit cyber security news
  • AvosLocker Ransomware Variant Using New Trick to Disable Antivirus Protection cyber security news
  • Researchers Warn of ‘Matanbuchus’ Malware Campaign Dropping Cobalt Strike Beacons cyber security news
  • New RIG Exploit Kit Campaign Infecting Victims’ PCs with RedLine Stealer cyber security news
  • Ukraine War Themed Files Become the Lure of Choice for a Wide Range of Hackers cyber security news
  • OpenSSL Releases Patch for High-Severity Bug that Could Lead to RCE Attacks cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Demand for Hardware Crypto Wallets Increases Amid Currency Restrictions in Russia – Bitcoin News
  • Cumberland Says Financially Burdened Crypto Firms Are ‘Hanging Over the Market Like a Cloud’ – Bitcoin News
  • Worst Quarterly Bitcoin Crash In A Decade Closes Above Key Support
  • Bitmain Launches 2,400 Megahash E9 Ethereum Miner Ahead of The Merge – Mining Bitcoin News
  • How This Company Lost 99% Of Its Clients Funds Shorting LUNA

Recent Comments

No comments to show.
  • GensoKishi’s MV Token to Be Listed on Kraken – Press release Bitcoin News bitcoin news
  • Kanye West Files Trademarks Describing NFT Technology After Denouncing the Digital Collectible Concept – Bitcoin News bitcoin news
  • Majority of Crypto Fund Managers Surveyed Predict Bitcoin Could Reach $100K by Year-End – Markets and Prices Bitcoin News bitcoin news
  • Top 3 Web3 Coins to Watch in 2022 bitcoin news
  • Polkadot’s 16th Parachain Slot Secured in Crowdloan Round bitcoin news
  • Bitcoin Reserve Risk Falls To 2015 Levels, What Happened That Year? bitcoin news
  • Bitcoin Steady Above $20K After Drop To $17K bitcoin news
  • In a Bear Market, Hold Onto Your Coins & Try to Earn More Cryptos bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme