Dark.IoT, OMIGOD & UDP Technology Update


2021年9月21日下午02:09

Over the past several months, Radware researchers have been monitoring the ongoing evolution of the Mirai variant campaign known as Dark.IoT. In August, we reported [1] that the operators behind the botnet had begun leveraging a vulnerability, CVE-2021-35395, in Realtek's SDK only a week after it was disclosed. This month, the operators of Dark.IoT integrated two new exploits in their most recent malware binaries.

CVE-2021-38647, also known as OMIGOD, was disclosed [2] by the Wiz Research Team on September 14 and is an unauthenticated Remote Code Execution vulnerability affecting more than half of all Microsoft Azure cloud instances. The second, CVE-2021-33544, was disclosed [3] in July of 2021 by RandoriSec and is a command injection vulnerability that impacts about a dozen IP camera manufacturers who use firmware by UDP Technology.

Read the Complete Alert
 

Background

In August of 2021, Radware Research reported [1] that a Mirai variant campaign known as Dark.IoT had begun leveraging a vulnerability in Realtek's SDK a week after its disclosure. Both Palo Alto Networks and Juniper Threat Labs reported [4] [5] seeing the operators behind Dark.IoT leveraging recently disclosed exploits within days, and in one case, within hours of publication. All three security firms, who are members of the Cyber Threat Alliance, agreed that the operators would continue to rapidly leverage recently disclosed vulnerabilities in an attempt to capture more vulnerable devices.

Radware is now reporting that the operators behind Dark.IoT again updated their binaries to include two new exploits. One of the new exploits allows Dark.IoT to move beyond IoT devices with constrained resources to capable Linux servers hosted in Azure clouds. Malicious actors targeting Linux cloud instances would typically leverage them for cryptomining operations. The Dark.IoT campaign, however, is aimed exclusively at leveraging infected instances for DDoS attacks. At the time of publication, the only payload embedded in the dropped malware binaries leveraging OMIGOD were the previously reported [1], well-known DDoS attack vectors.

OMIGOD VULNERABILITY

On September 14, 2021, the Wiz Research Team disclosed [2] a series of critical vulnerabilities affecting the Azure Open Management Infrastructure (OMI) agent. The OMI agent is deployed automatically in Linux instances when Azure customers enable certain Azure services, without their knowledge. Wiz named the quartet of zero-days “OMIGOD.” They conservatively estimated that thousands of Azure customers and millions of endpoints could be affected. In the small sample of Azure tenants they analyzed, over 65% were unknowingly at risk.

Microsoft issued CVEs for OMIGOD and made a patch available to customers during their September, 2021 Patch Tuesday release:

Microsoft updated its advisory [10] on September 18, announcing an auto-update for their PaaS service offerings that use vulnerable VM extensions by September 22, 2021. Microsoft also clarified which instances will still require manual patching.

The Wiz Research Team blog includes all information needed to weaponize the vulnerability. The first Python based proof-of-concept was published on Github by September 15, 2021.

The operators behind the Dark.IoT botnet demonstrated their ability to leverage and test recently disclosed vulnerabilities quickly. In some cases, the operators have been able to incorporate exploits within hours of publication. With the most recent updates to the Dark.IoT botnets, Radware’s deception network recorded OMIGOD exploits carrying the Dark.IoT signature (“Agent-Header: Dark”) starting September 15, 2021, only a few hours after the proof of concept was made public.

Continue Reading...

Click here to read the full ERT Threat Alert.

Read the full threat alert now

 

与Radware销售部门接洽

我们的专家将回答您的问题、评估您的需求,并帮助您了解哪些产品最适合您的业务。

已经是客户?

无论您需要支持或更多服务,还是需要解答有关我们产品和解决方案的问题,我们都会随时提供帮助。

公司地点
马上从知识库获得答案
获得免费在线产品培训
联系Radware技术支持部
加入Radware客户计划

参与社交

联系专家并加入有关Radware技术的对话。

Blog
安全研究中心
CyberPedia