Threat Advisory

NoaBot: A Mirai-Based Botnet with Unique SSH Tactics and Cryptomining Capabilities

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A recently discovered crypto mining campaign, named NoaBot, has been identified by researchers. This sophisticated malware has been active, utilizing a modified Mirai botnet over the SSH protocol. The campaign exhibits a high level of operational security, showcasing characteristics of mature threat actors. However, the attribution is complicated due to the seemingly childish naming conventions within the malware's binaries.[/subscribe_to_unlock_form]

Summary:

A recently discovered crypto mining campaign, named NoaBot, has been identified by researchers. This sophisticated malware has been active, utilizing a modified Mirai botnet over the SSH protocol. The campaign exhibits a high level of operational security, showcasing characteristics of mature threat actors. However, the attribution is complicated due to the seemingly childish naming conventions within the malware's binaries.[emaillocker id="1283"]

NoaBot, a Mirai-based botnet, distinguishes itself with unique features and evolutions compared to the original Mirai botnet. Unlike Mirai, NoaBot's spreader is based on SSH, utilizing a custom-made scanner with an unconventional behavior of sending a "hi" string upon connection. Additionally, the malware includes embedded song lyrics, initially from the song "Who's Ready for Tomorrow" by Rat Boy and IBDY. Noteworthy changes from Mirai involve a different credential dictionary for the SSH scanner and the incorporation of postbreach capabilities, such as installing a new SSH authorized key for backdoor access. The botnet's compilation with uClibc and string obfuscation contributes to its evasion of traditional antivirus signatures.

The mining aspect of the campaign involves a modified XMRig miner, which obfuscates its configuration and utilizes a custom mining pool to obscure the wallet address. Surprisingly, the wallet address is intentionally omitted, suggesting that the threat actors run a private pool. The evolution of the campaign includes the addition of command line arguments, with the "noa" flag ensuring persistence through a crontab entry. Furthermore, newer samples exhibit more sophisticated postbreach operations do not present in earlier versions. The campaign's switch from Mirai to the P2PInfect worm, written in Rust, introduces custom code, potentially indicating the threat actors' curiosity or desire for more challenging malware development.

While NoaBot may seem like another Mirai variant coupled with an XMRig cryptominer, its complexity lies in the obfuscations and modifications introduced by the threat actors. Despite demonstrating technical proficiency, the inclusion of seemingly immature elements, such as profanities and gaming pop song lyrics, aids in associating NoaBot with the P2PInfect worm. The campaign's global distribution highlights its wormable nature, turning victims into attackers. Mitigation strategies involve restricting SSH access and using strong passwords. Detection methods include monitoring for specific binary names and potential cron job installations. NoaBot serves as a reminder that even seemingly familiar threats can possess unique attributes that necessitate vigilance and adaptive cybersecurity measures.

Threat Profile:

 

References:

The following reports contain further technical details:

https://thehackernews.com/2024/01/noabot-latest-mirai-based-botnet.html

[/emaillocker]
crossmenu