Chalubo is a new botnet that targets servers and IoT devices that are not properly secured. When they become infected, they become part of the botnet and launch DDoS attacks.

Sophos researchers said this week that Chalubo appears to be growing rapidly as it appears to be targeting servers using the SSH service. The bot combines two very basic characteristics that we have seen before. First, it has adopted techniques used by malware on Windows to be able to “hide” its existence. Later, it appears that this botnet uses pieces of code from XOR.DDoS and Miraa. The Mirai botnet managed to disable many services in America and Europe about 3 years ago.
The same Sophos researchers, analyzing the Chalubo installer, have observed that there are many different versions to infect all kinds of systems, such as 32 and 64‑bit ARM systems, X86, X86‑64, MIPS, MIPSSEL and PowerPC. The first attack recorded by the botnet took place in the last days of August, and a few days later, on September 6, Sophos detected it in one of its honeypots, where it was taken for analysis.
Chalubo attempted to gain access to the Honeypot by brute-forcing, and while the botnet administrators believed they succeeded, the researchers actually deliberately gave it access to a user with root privileges, so they could see the commands used to disable the firewall protection. The main part of the installer was encrypted, but during its execution, a specific command stood out, the libsdes.
During execution, libsdes creates an empty folder so the installer can determine if it has already run on this system. Then an attempt is made to copy the botnet into a new folder under the path /usr/bin/ with a random name that includes letters and numbers. The purpose of the copying is to have multiple points from which it can be executed, in case it is terminated or the server is restarted.
“This particular bot exhibits great complexity compared to the corresponding bots that circulate for Linux systems.” Sophos reports. “Beyond the fact that the attack is completed with multiple correctly structured layers, the encryption used is an additional nuance that we do not see often”.
Sophos researchers believe that the end of the testing period for Chalubo is nearing, and they expect DDoS attacks in the near future. Finally, one thing is certain: Chalubo is not the only threat.
