A new botnet has emerged that appears to be even more threatening than Mirai and Qbot. Security researchers at Bitdefender have revealed that the new botnet, dubbed Dark_nexus, has certain characteristics and properties that make it stand out from other modern malware botnets.
But what are botnets?
The term “botnet” comes from the words robot and network. Botnets are computer networks, IoT (Internet of Things) products, and mobile devices that have been infected by hackers with malware. Botnets can be used for DDoS attacks, distributing spam emails, spreading viruses, stealing data, and other malicious activities.
Dark_nexus, named for the strings in its banner, shares some similarities with Mirai and Qbot, but most of its functionality is original. For example, the way some of its modules were developed makes it much more powerful, according to Bitdefender. Dark_nexus is a botnet that has been active for three months, and three variants have been released during this time. In addition, honeypots have revealed that there are at least 1,372 bots connected to the botnet, most of which are located in China, the Republic of Korea, Thailand and Brazil. To compromise a device, the botnet uses elements associated with credentials and exploits any errors. Two modules, one synchronous and one asynchronous, are also used, aiming to use the Telnet and predefined lists of credentials to gain access to the targeted device. Additionally, the malware attempts to hide its actions by renaming itself to /bin/busybox. The botnet has a payload that can be adapted to 12 different CPU and is delivered depending on the settings the victim has made on the device. It also connects to two servers and a report server, which receives reports about vulnerable services that contain IP and port numbers.

The attacks carried out by this botnet are generally typical, with one exception – the command browser_http_req. Bitdefender notes that this element is “extremely complex and configurable” and “tries to conceal the traffic, presenting it as harmless traffic that could have been generated by a web browser”. Another interesting characteristic is the attempt to prevent a device from restarting. The cron service is violated and interrupted, and the appropriate functions to restart a device cannot be executed. It is worth noting that the botnet's programmer is believed to be Greek. Finally, researchers found socks5 proxies in some variants of the malware, a characteristic also observed in botnets such as the variants of Mirai, TheMoon and Gwmndy, and they continue to monitor the evolution of the botnet with interest.
