Threat Advisory

Gafgyt Botnet Variant Targets Cloud Servers for GPU Cryptocurrency Mining

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new variant of the Gafgyt botnet has been identified, targeting machines with weak SSH passwords. Unlike traditional Gafgyt attacks that focus on Internet of Things (IoT) devices, this campaign extends its reach to more robust servers in cloud-native environments, leveraging their computational power for cryptomining activities. The campaign underscores the evolving nature of IoT botnets, which are now exploiting cloud resources for malicious purposes.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new variant of the Gafgyt botnet has been identified, targeting machines with weak SSH passwords. Unlike traditional Gafgyt attacks that focus on Internet of Things (IoT) devices, this campaign extends its reach to more robust servers in cloud-native environments, leveraging their computational power for cryptomining activities. The campaign underscores the evolving nature of IoT botnets, which are now exploiting cloud resources for malicious purposes.[emaillocker id="1283"]

 

The attack begins with a successful brute-force attempt on an SSH server with weak credentials. Upon gaining access, the attacker executes two ELF binaries in memory: "ld-musl-x86," a Gafgyt SSH scanner, and "systemd-net," an XMRIG cryptominer. The malware checks for existing infections and competing malware, terminating them before initiating the cryptomining and botnet expansion processes. Notably, the cryptominer is configured to utilize GPU power, indicating a focus on high-performance cloud servers. The binaries masquerade as legitimate Linux system components, aiding in defense evasion, and target a wide range of systems, from IoT devices to cloud-native environments.

 

In conclusion, this Gafgyt form represents a significant evolution from previous iterations, targeting cloud-native environments with robust computing capabilities. Organizations utilizing SSH for remote server management must ensure strong password policies and monitor for suspicious behavior. Implementing runtime protection and auditing capabilities, as demonstrated in this case, is essential for detecting and mitigating such advanced threats in real time.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1059 Command and Scripting Interpreter
Defense Evasion T1070 Indicator Removal
Credential Access  T1110 Brute Force
Discovery  T1046 Network Service Discovery
T1082 System Information Discovery
Command and Control T1071 Application Layer Protocol
T1105 Ingress Tool Transfer
Exfiltration T1041 Exfiltration Over C2 Channel
 Impact  T1496 Resource Hijacking

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/08/new-gafgyt-botnet-variant-targets-weak.html

[/emaillocker]
crossmenu