Cybercriminals managed to assemble a gigantic botnet with more than 40,000 infected devices for the purpose of creating cryptocurrencies and redirecting users to malicious sites.

The botnet was named Prowli and was discovered by the security team GuardiCore.
Its operation is complex and relies on system vulnerabilities combined with brute-force attacks to infect and take control of computer systems.
At the same time, an SSH scanner is launched that tries to guess the username and password of devices that expose their SSH port to the Internet.
Most of the infected devices were:
• WordPress
• Joomla! Sites with the K2 extension (via CVE-2018-7482 )
• Several DSL modem models (via known vulnerability )
• Servers running HP Data Protector (via CVE-2014-2623 )
• Drupal, PhpMyAdmin, NFS, and servers with exposed SMB ports (all via brute-force attack)

Prowli has the ability to identify infected devices that have enough resources to be used for cryptocurrency creation. Systems that are sufficiently powerful also receive a miner for Monero as well as the R2R2 WORM so that Prowli can expand faster to other networks.
The overall Prowli campaign was deliberately designed and optimized to maximize the profits of the scammers.

Overall, it managed to infect more than 40,000 servers and devices across the networks of 9,000 companies, which were then fully exploited to make money, before the malicious software was detected on them. It obviously operated without discrimination and dealt with computer systems worldwide, regardless of the operating system they used.
