Dark.IoT Botnet


August 24, 2021 11:18 AM

Over the past several months, Radware researchers have been monitoring the evolution of a Mirai variant we have named "Dark.IoT."

Read the Complete Alert
 

Background

On March 15th, Unit 42 researchers at Palo Alto Networks published an alert [1] about a new Mirai variant rapidly integrating recently disclosed vulnerabilities. Palo Alto Networks reported that the threat actors behind the botnet leveraged CVE-2021-27561 and CVE-2021-27562 within hours of the vulnerabilities' being published. They also noted that the operators were testing several other exploits over the following weeks, including CVE-2021-22502 and CVE-2020-26919. In total, Palo Alto Network said that the operators attempted to leverage five known and three unknown vulnerabilities.

On August 6th, Juniper Threat Labs published a report [2] about a Mirai variant seen propagating in the wild via CVE-2021-20090, a supply chain vulnerability recently disclosed by Tenable [3], that impacts IoT devices manufactured by nearly two dozen vendors that all leverage Arcadyan firmware in their devices. Juniper Threat Labs discovered that this botnet was using the same naming conventions and was rapidly leveraging new exploits, like the one found by Palo Alto Networks. For example, the operators behind the botnet leveraged CVE-2021-20090 just two days after Tenable published the vulnerability details. Juniper Threat Labs reported that the botnet, at the time, was attempting to test for and exploit six known vulnerabilities tracked by a CVE as well as several other unassigned exploits.

On August 19th, Radware researchers found that new malware binaries were published on both loaders leveraged in the campaign. While reviewing the new binaries, we discovered that the operators behind the botnet had incorporated and are presently preparing to leverage yet another supply chain vulnerability: CVE-2021-35395. This vulnerability was recently disclosed [4] by IoT Inspectors Research Lab on August 16th and impacts IoT devices manufactured by 65 vendors relying on the Realtek chipsets and SDK.

Dark.IoT

The operators behind the Dark.IoT botnet have been developing this variant of the Mirai botnet since February of 2021. We named the botnet Dark.IoT based on the use of 'Dark.[architecture]' filenames for its malware binaries and the reoccurring use of 'lmaoiot' variations throughout its infrastructure naming.

As Palo Alto Networks reported in March of 2021, Dark.IoT still tries to delete contents of key system folders /tmp and /var/log from targeted devices when executing the 'lolol.sh' loader script on new victims. In addition, the shell script leverages the killall command to terminate both legitimate and competing bot processes running on the device before downloading Dark.IoT binaries.

Continue Reading...

Click here to read the full ERT Threat Alert.

Read the full threat alert now

 

与Radware销售部门接洽

我们的专家将回答您的问题、评估您的需求,并帮助您了解哪些产品最适合您的业务。

已经是客户?

无论您需要支持或更多服务,还是需要解答有关我们产品和解决方案的问题,我们都会随时提供帮助。

公司地点
马上从知识库获得答案
获得免费在线产品培训
联系Radware技术支持部
加入Radware客户计划

参与社交

联系专家并加入有关Radware技术的对话。

Blog
安全研究中心
CyberPedia