Summary:
A new Python-based hacking tool, known as FBot, has emerged on the cyber threat landscape, displaying distinct characteristics in its approach to compromising web servers, cloud services, and Software-as-a-Service (SaaS) platforms. Unlike its counterparts, FBot stands out by not utilizing the widely used Androxgh0st code commonly found in similar cloud malware families. Instead, it shares similarities with the Legion cloud infostealer, indicating a unique development path. FBot focuses on credential harvesting, particularly for AWS, Office365, PayPal, Sendgrid, and Twilio, with a secondary emphasis on enabling spamming attacks. Notably, its smaller footprint suggests private development and a targeted distribution approach.[/subscribe_to_unlock_form]
Summary:
A new Python-based hacking tool, known as FBot, has emerged on the cyber threat landscape, displaying distinct characteristics in its approach to compromising web servers, cloud services, and Software-as-a-Service (SaaS) platforms. Unlike its counterparts, FBot stands out by not utilizing the widely used Androxgh0st code commonly found in similar cloud malware families. Instead, it shares similarities with the Legion cloud infostealer, indicating a unique development path. FBot focuses on credential harvesting, particularly for AWS, Office365, PayPal, Sendgrid, and Twilio, with a secondary emphasis on enabling spamming attacks. Notably, its smaller footprint suggests private development and a targeted distribution approach.[emaillocker id="1283"]
FBot demonstrates its prowess through a set of key features. Within its AWS-targeting capabilities, the tool employs an AWS API Key Generator that randomly generates AWS access key IDs and secret keys. Additionally, FBot includes a Mass AWS Checker to inspect AWS Simple Email Service (SES) configurations for spamming optimization, even creating a new user account with elevated privileges. The third AWS-related function, AWS EC2 Checker, allows checking EC2 service quotas across different regions. FBot also delves into targeting payment services, featuring a PayPal Validator that verifies PayPal account status through a Lithuanian fashion designer's website. Further, FBot extends its reach to SaaS platforms, offering a Sendgrid API Key Generator and a Twilio feature to gather details about Twilio accounts. In the realm of web frameworks, FBot exhibits a Hidden Config Scanner that validates URLs hosting Laravel environment files. This feature can extract credentials from various configuration files related to AWS, MandrillApp, Office365, Sendgrid, Twilio, and more. FBot extends its focus to popular Content Management Systems (CMS) using the cms_scanner function, detecting technologies like WordPress, Joomla, Drupal, Magento, and others. The tool's reliance on configuration values, either through an .ini file or headers, adds a layer of sophistication to its operations. The presence of a compiled Windows executable version suggests a versatility in deployment.
FBot represents a notable addition to the landscape of cloud attack tools, exhibiting a blend of innovation and familiarity. While it forges its path by eschewing the Androxgh0st code, FBot shares intriguing connections with the Legion cloud infostealer. The tool's relatively small size and consistent use of the iDevXploit handle suggest a focused and potentially private development effort. The absence of references to open-source code differentiates FBot from other cloud hacktools, reflecting a bespoke nature tailored for individual buyers. As organizations navigate this evolving threat landscape, it is imperative to prioritize security measures, including enabling multi-factor authentication for AWS services and implementing vigilant monitoring for new user accounts and configuration changes in SaaS applications.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2024/01/new-python-based-fbot-hacking-toolkit.html
[/emaillocker]