200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
#1
Quote:The botnet which was once a DoS-focused botnet targeting Windows, Linux, Android, and enterprise IoT devices created by the Outlaw group has recently been upgraded to also mine for Monero and to propagate using SSH brute-force attacks.

As initially discovered by the Trend Micro's Cyber Safety Solutions Team, this botnet was created by a Romanian threat group dubbed Outlaw which used the servers of a Japanese art institution and a Bangladeshi government website as command-and-control (C&C) servers.

The attacking bots who are part of the network will use a malicious tool named haiduc to scan for and attack systems vulnerable to the CVE-2017-1000117 command injection vulnerability.
Once it manages to compromise a host, the bot will automatically download a min.sh script which comes in two variants, each of them designed to use different attacks.

A full list of Indicators of Compromise (IOCs) is available on Trend Micro's TrendLabs Security Intelligence Blog.

Source: https://news.softpedia.com/news/200k-out...3888.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Sysinternals Suite 3.26.2026
What's New (March ...harlan4096 — 11:40
AxCrypt 3.0.0.83
AxCrypt 3.0.0.83: ...harlan4096 — 11:39
Microsoft Edge 146.0.3856.84
Version 146.0.3856...harlan4096 — 11:37
PowerToys 0.98.1
Release v0.98.1 ...harlan4096 — 11:37
Opera 129.0.5823.28
Hello! A new Op...harlan4096 — 11:36

[-]
Birthdays
Today's Birthdays
avatar (46)qaqapeti
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>