EXECUTIVE SUMMARY
A new variant of the Gafgyt botnet has been identified, targeting machines with weak SSH passwords. Unlike traditional Gafgyt attacks that focus on Internet of Things (IoT) devices, this campaign extends its reach to more robust servers in cloud-native environments, leveraging their computational power for cryptomining activities. The campaign underscores the evolving nature of IoT botnets, which are now exploiting cloud resources for malicious purposes.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A new variant of the Gafgyt botnet has been identified, targeting machines with weak SSH passwords. Unlike traditional Gafgyt attacks that focus on Internet of Things (IoT) devices, this campaign extends its reach to more robust servers in cloud-native environments, leveraging their computational power for cryptomining activities. The campaign underscores the evolving nature of IoT botnets, which are now exploiting cloud resources for malicious purposes.[emaillocker id="1283"]
The attack begins with a successful brute-force attempt on an SSH server with weak credentials. Upon gaining access, the attacker executes two ELF binaries in memory: "ld-musl-x86," a Gafgyt SSH scanner, and "systemd-net," an XMRIG cryptominer. The malware checks for existing infections and competing malware, terminating them before initiating the cryptomining and botnet expansion processes. Notably, the cryptominer is configured to utilize GPU power, indicating a focus on high-performance cloud servers. The binaries masquerade as legitimate Linux system components, aiding in defense evasion, and target a wide range of systems, from IoT devices to cloud-native environments.
In conclusion, this Gafgyt form represents a significant evolution from previous iterations, targeting cloud-native environments with robust computing capabilities. Organizations utilizing SSH for remote server management must ensure strong password policies and monitor for suspicious behavior. Implementing runtime protection and auditing capabilities, as demonstrated in this case, is essential for detecting and mitigating such advanced threats in real time.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1059 | Command and Scripting Interpreter |
| Defense Evasion | T1070 | Indicator Removal |
| Credential Access | T1110 | Brute Force |
| Discovery | T1046 | Network Service Discovery |
| T1082 | System Information Discovery | |
| Command and Control | T1071 | Application Layer Protocol |
| T1105 | Ingress Tool Transfer | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1496 | Resource Hijacking |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/08/new-gafgyt-botnet-variant-targets-weak.html