-Remaiten threatens users' security by carrying out attacks through home routers.[su_spacer size=”2″]
-All devices with an open Telnet port are at risk.[su_spacer size=”2″]
-What users should do to protect themselves.[su_spacer size=”2″]
Malware developers have created a new DDoS bot called Remaiten, which targets home routers running on common Linux architectures, and shows several similarities to other powerful DDoS bots, such as Tsunami and Gafgyt.
The way Remaiten works is very simple. The creators of this bot use an automated system that scans interconnected routers and attempts to access them via Telnet port(23).
If this port is open, Remaiten tries different, basic combinations of usernames and passwords. If a device is not secured with strong passwords and has the default factory settings, the DDoS Bot can easily gain access to it and infect it with simple malware.
This mode of operation has been copied from the DDoS bot Gafgyt, which operates in the same way. The main difference from Gafgyt is that this variant of the malware, once it gains access to the device, detects the router architecture and downloads the appropriate Remaiten bot. At this stage, Gafgyt would similarly attempt to download all available binaries and run each one individually until one compatible with the infected device is found. However, by scanning the platform and downloading a single binary, Remaiten leaves very little evidence behind.
[su_button url=”https://www.secnews.gr/102569/to-18-tou-web-traffic-proerxetai-apo-kakoboula-bot/” target=”blank” style=”glass8″ wide=”yes” center=”yes”]18% of web traffic comes from malicious bots[/su_button]
Once the router is infected with Remaiten, the bot immediately registers it with its C&C servers. The C&C server is essentially a real IRC channel, as all communications are done via the IRC (Internet Relay Chat) protocol. Criminals can send commands to all bots via IRC messages, ordering them to launch DDoS attacks against various targets.
Additionally, Remaiten has the ability to remove any other bots it detects on the router, in order to ensure the utilization of all the device's resources.
ESET's research team reports that the Remaiten bot targets routers running on MIPS, ARM, Power PC, and Super H architectures.

