HomeSecuritySmominru Botnet: Compromised 90,000 Windows via EternalBlue Exploit

Smominru Botnet: Compromised 90,000 Windows via EternalBlue Exploit

The hackers behind the Smominru botnet compromised nearly 90,000 Windows computers last month using the EternalBlue exploit and performing brute force attacks on MS-SQL, RDP, Telnet services.

A researcher revealed that the botnet infects more than 4000 systems daily, and takes control by exploiting vulnerabilities in unpatched systems.

Botnet

The Smominru botnet targets several countries, including China, Taiwan, Russia, Brazil, and the US where there were several thousand infected systems in educational institutions, medical companies, and even some cybersecurity companies.

Criminals do not focus on specific targets, they simply launch the attack and compromise any system that has vulnerable servers.

The Smominru botnet is distributed as a worm, so if it infects one of the network's systems, it spreads to other networks in the organization.

Windows 7 and Windows Server 2008 are the most infected systems with 85% of these versions being highly vulnerable to the ExternalBlue exploit.

How does Smominru Botnet infect a system?

The attackers behind Smoninru use a Powershell script called blueps.txt that crashes the victim's machine - as the first stage of infection - and starts executing binaries as well as additional functions.

Smominru Botnet

They later create a new admin user called admin$ and download the additional scripts to execute the malicious process.

Also, many backdoors from the infected device to perform various functions, such as creating new users and scheduled tasks.

The Smominru botnet disables and blocks other campaigns on the infected machine and deletes the relevant file of the existing malicious campaign.

During the infection process, the botnet blocks various TCP ports (SMB, RPC) in order to prevent other attackers from compromising their infected machines.

Smominru Botnet: Compromised 90,000 Windows via EternalBlue Exploit

Smominru Botnet Worm Module

As we discussed above, the binary files from blueps.txt contain various malicious programs, such as worm downloader (u.exe / ups.exe), Trojan horse (upsupx.exe), and MBR rootkit (max.exe / ok.exe).

A u.exe worm module is responsible for downloading DLL from the command and control server that scans the network, detects vulnerabilities, and reports them.

Another executable file removes the open-source Trojan called PcShare which is capable of downloading and installing, command and control, taking screenshots, stealing information and has been used primarily to download the Monecrypto miner.

The hackers behind this attack used nearly 20 servers as part of the botnet, and most of the servers are hosted in the U.S., with some hosted by ISPs in Malaysia and Bulgaria.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS