
A new series of malicious Roboto Botnet activities has come to light, which exploits the RCE vulnerability to attack Linux.
The first to discover the Roboto Botnet was Netlab360, which described it as an ELF (Executable Linkable Format) file. The first discovery was made in August, while Honeypot later detected another suspicious ELF sample, which acted as a downloader to download the bot in question.
For the past three months, security researchers have been continuously monitoring Roboto's movements and activities to discover its goals and the methods it uses.
It has been discovered that the Roboto Botnet uses algorithms such as Curve25519, Ed25519, TEA, SHA256, HMAC-SHA256, to maintain its integrity, protect itself, and gain persistent control over Linux Webmin servers.
According to the researchers: “The botnet has DDoS functionality , but it seems that DDoS attacks are not its main purpose. We have not yet detected any DDoS attacks since we discovered it. We still need to learn its real purpose.”
Researchers observed Roboto spreading via 51.38.200.230 (Webmin Honeypot service) and the downloader sample spreading via the Webmin RCE vulnerability (CVE-2019-15107).
The download URL https://190.114.240.194/boot helps spread the payload.
The main purpose of Roboto downloader is to download the encrypted Roboto Bot program from a specific URL .Later, the malicious program will decrypt it and execute it.
Roboto Botnet can perform a variety of advanced operations, such as reverse shell, automatic uninstallation, network information collection, bot, system command execution, execution of encrypted files specializing in URLs, DDoS attacks, and more.
Roboto provides the ability to execute a DDoS attack through the following methods:
CMP Flood
HTTP Flood
TCP Flood
UDP Flood
Netlab360 recommends that Webmin users examine whether they have been infected by checking the process, file name, and UDP network connection, and block all IPs, URLs, and domain names associated with the Botnet.
