More and more malware developers are turning to the IoT space after the success of the infamous Mirai and due to the large volume of vulnerable devices.
Recent large-scale attacks demonstrate that the IoT provides fertile ground for the development of dangerous botnets that are leveraged to carry out massive DDoS attacks.
In this context, it is no surprise that malware authors are now focusing their efforts on the IoT space, constantly developing new threats in the hope of building the next Mirai botnet.
One of the latest additions to the IoT threat landscape is the dangerous Linux/NyaDrop trojan, which was recently reverse engineered by MalwareMustDie, the security researcher who discovered the Mirai malware.
According to the researcher, NyaDrop first appeared in May, but was much simpler and less dangerous. Following the success of Mirai, which is still being used for large-scale attacks, a new variant of NyaDrop has been released – following in its footsteps – targeting the IoT space.
Just like most IoT malware these days, the authors of NyaDrop rely on compromising vulnerable devices with default access credentials via brute-force attacks. MalwareMustDie reports that the attacks are carried out on the devices' Telnet ports, which is a common practice in IoT attacks.
NyaDrop acts as a “dropper” for the Nya malware
When attackers gain access to a vulnerable device through brute force, a series of automated commands are executed that download and execute NyaDrop. The NyaDrop trojan is very small in size because it acts as a “dropper,” a term used to describe malware that downloads additional malware. In this case, NyaDrop is used to download “Nya,” a Linux binary, from which it gets its name.


