Threat Advisory

New Medusa Botnet Emerging Via Mirai Botnet Targeting Linux Users

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

 Recently, researchers discovered a variant of the Mirai botnet that was downloading and propagating a new botnet called the "Medusa Botnet".Mirai is an active botnet that exploits vulnerabilities in networking devices running Linux. The botnet exploits these flaws in devices such as routers, IP cameras, and IoT devices to gain complete control of the machine. When the Mirai botnet is activated, it connects to the command and control server and retrieves the "medusa stealer.sh" file. The medusa stealer.sh file that was downloaded contains the commands for downloading and executing Medusa malware files on Linux machines. Further, it is used for dropping various payloads on infected machines.[/subscribe_to_unlock_form]

Summary:

 Recently, researchers discovered a variant of the Mirai botnet that was downloading and propagating a new botnet called the "Medusa Botnet".Mirai is an active botnet that exploits vulnerabilities in networking devices running Linux. The botnet exploits these flaws in devices such as routers, IP cameras, and IoT devices to gain complete control of the machine. When the Mirai botnet is activated, it connects to the command and control server and retrieves the "medusa stealer.sh" file. The medusa stealer.sh file that was downloaded contains the commands for downloading and executing Medusa malware files on Linux machines. Further, it is used for dropping various payloads on infected machines.[emaillocker id="1283"]

Threat Profile:

References:

The following reports contain further technical details:

https://blog.cyble.com/2023/02/03/new-medusa-botnet-emerging-via-mirai-botnet-targeting-linux-users/

[/emaillocker]
crossmenu