EXECUTIVE SUMMARY
A new Distributed Denial of Service campaign, dubbed "Panamorfi," has been uncovered, targeting misconfigured Jupyter notebooks. The campaign, orchestrated by the threat actor utilizes the Java-based Minecraft DDoS package "mineping" to execute TCP flood attacks. The attack method capitalizes on vulnerabilities in exposed Jupyter notebook environments, posing a significant risk to cloud-native infrastructure.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A new Distributed Denial of Service campaign, dubbed "Panamorfi," has been uncovered, targeting misconfigured Jupyter notebooks. The campaign, orchestrated by the threat actor utilizes the Java-based Minecraft DDoS package "mineping" to execute TCP flood attacks. The attack method capitalizes on vulnerabilities in exposed Jupyter notebook environments, posing a significant risk to cloud-native infrastructure.[emaillocker id="1283"]
The attack begins with the threat actor gaining initial access through an exposed Jupyter notebook, where they execute a command to download a malicious zip file from an external source. This file, which is new and largely undetected by antivirus solutions, contains two Java Archive (JAR) files named conn.jar and mineping.jar. The conn.jar file initiates the attack by connecting the victim’s machine to a Discord channel, where the threat actor coordinates the DDoS attack. The mineping.jar file, a known Minecraft server DDoS tool, is then loaded to launch a TCP flood attack, overwhelming the target server with many connection requests. The progress and results of the attack are continuously updated in the Discord channel.
This attack highlights the importance of securing Jupyter notebooks, which are commonly used by data professionals who may not always prioritize security. The Panamorfi DDoS campaign underscores the need for robust runtime protection and configuration management. Utilizing it is possible to detect and block such malicious activities in real-time, preventing the execution of unauthorized code and effectively neutralizing the threat before any damage is done.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1059 | Command and Scripting Interpreter |
| T1053 | Scheduled Task/Job | |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1070 | Indicator Removal | |
| T1078 | Valid Accounts | |
| Command and Control | T1071 | Application Layer Protocol |
| Impact | T1489 | Service Stop |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/08/hackers-exploit-misconfigured-jupyter.html