HomeSecurityLinux Botnet Targets Systems Vulnerable to Bluekeep Vulnerability

Linux Botnet Targets Systems Vulnerable to Bluekeep Vulnerability

BluekeepA new variant of the WatchBog malware has emerged. It is a Linux-based cryptomining malware botnet that, according to researchers, has the ability to scan the Internet for Windows RDP servers vulnerable to the Bluekeep vulnerability.

BlueKeep is a highly critical vulnerabilitythat allows remote code execution in Windows Remote Desktop Services. This could allow an attacker to gain complete control over vulnerable systems.

In May, Microsoft released a patch for the BlueKeep vulnerability (CVE-2019-0708), however, more than 800,000 Windows computersaccessible via the Internet are still vulnerable.

Researchers believe that the hackers behind WatchBog are using their botnet network to prepare “a list of vulnerable systems, which they intend to target in the future or sell to third parties.”

The BlueKeep scanner, included in WatchBog, scans the Internet and finds new vulnerable computers.

Linux Botnet Targets Systems Vulnerable to Bluekeep Vulnerability

According to the researcher who discovered the new WatchBog variant, the malware has already compromised over 4,500 Linux machines in the last two months .

WatchBog has been used by hackers since late last year. However, the new variant, which exploits the Bluekeep vulnerability, is part of a campaign that has been underway since early June.

The new WatchBog variant includes new exploit capabilities and attempts to exploit some recently patched vulnerabilities in Linux applications . This allows hackers to compromise more Linux systems even faster.

The WatchBog Linux botnet malware has many functions, targeting vulnerabilities in Exim, Jira, Solr, Jenkins, ThinkPHP and Nexus applications, as we have mentioned in a previous article:

Pwn Module

  • CVE-2019-11581 (Jira)
  • CVE-2019-10149 (Exim)
  • CVE-2019-0192 (Solr)
  • CVE-2018-1000861 (Jenkins)
  • CVE-2019-7238 (Nexus Repository Manager 3)

Scanning Module

  • BlueKeep Scanner
  • Jira Scanner
  • Solr Scanner

Brute-forcing Module

Spreading Module

  • Apache ActiveMQ (CVE-2016-3088)
  • Solr (CVE-2019-0192)
  • Code execution via Redis

After scanning and brute-forcing, WatchBog installs a script on the targeted machine, which downloads the Monero miner (see more about the attack here).

Security experts recommend that users and administrators of Linux and Windows systems keep their software and operating systems updated to protect themselves from known vulnerabilities and avoid attacks from hackers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS