Summary:
A newly identified malware, named NKAbuse has emerged as a significant threat by leveraging the NKN (New Kind of Network) technology for data exchange. Notably, NKAbuse is the first malware to exploit the NKN protocol, a decentralized peer-to-peer network protocol that incorporates blockchain for secure and transparent network operations. NKN aims to optimize data transmission speed and latency, boasting approximately 60,710 nodes in its network, enhancing robustness, decentralization, and the ability to handle substantial data volumes. The malware, primarily targeting Linux desktops in Mexico, Colombia, and Vietnam, exhibits a stealthy nature, making it a challenging threat to trace and mitigate.[/subscribe_to_unlock_form]
Summary:
A newly identified malware, named NKAbuse has emerged as a significant threat by leveraging the NKN (New Kind of Network) technology for data exchange. Notably, NKAbuse is the first malware to exploit the NKN protocol, a decentralized peer-to-peer network protocol that incorporates blockchain for secure and transparent network operations. NKN aims to optimize data transmission speed and latency, boasting approximately 60,710 nodes in its network, enhancing robustness, decentralization, and the ability to handle substantial data volumes. The malware, primarily targeting Linux desktops in Mexico, Colombia, and Vietnam, exhibits a stealthy nature, making it a challenging threat to trace and mitigate.[emaillocker id="1283"]
NKAbuse, as discovered by researchers stands out for its innovative use of the NKN public blockchain protocol, employing it for both flooding attacks and as a backdoor within Linux systems. Exploiting an old Apache Struts flaw CVE-2017-5638 in one instance, the malware demonstrates its versatility by compromising not only Linux computers but also IoT devices, supporting MIPS, ARM, and 386 architectures. The malware's abuse of NKN facilitates DDoS attacks that are difficult to trace, benefiting from the obscurity of the novel protocol. The malware communicates with the bot master through NKN, enabling a range of concurrent channels for resilient communication. Beyond DDoS capabilities, NKAbuse acts as a remote access trojan (RAT), granting attackers control over compromised systems for command execution, data exfiltration, and even capturing screenshots. This multifaceted functionality, coupled with the use of blockchain technology, poses a significant challenge for defense against NKAbuse.
NKAbuse presents a notable advancement in the realm of malware, leveraging the novel NKN protocol to establish a stealthy and adaptable threat. Its primary focus on Linux desktops, coupled with the ability to compromise IoT devices, underscores the breadth of its impact. The malware's utilization of NKN for DDoS attacks, combined with its role as a remote access trojan, sets it apart in the threat landscape. The blockchain technology employed not only ensures the availability of the malware but also complicates efforts to trace and mitigate attacks. Defending against NKAbuse becomes particularly challenging due to its unique combination of advanced features and the use of an unconventional communication protocol. As cybersecurity threats continue to evolve, NKAbuse serves as a reminder of the need for vigilance and innovative defense strategies to counter increasingly sophisticated malware.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]