HomeSecurityHacker operated botnet for 8 years to download anime videos

Hacker operated botnet for 8 years to download anime videos

anime videos

For about eight years, a hacker had compromised devices D-Link NVR (network video recorders) and NAS and made them part of a botnet whose sole purpose was to connect to websites and download anime videos.

The botnet was called Cereals and first appeared in 2012. It reached its peak in 2015, when it amassed more than 10,000 bots.

However, despite its size, the botnet went unnoticed by most cybersecurity companies . Now, Cereals is slowly disappearing as the vulnerable devices it relied on over the years began to age and become inoperable. In addition, the decline of the Cereals botnet was also due to the emergence of a ransomware called Cr1ptT0r, which deleted the Cereals malware from many D-Link systems in the winter of 2019.

Now that both the botnet and the vulnerable devices are gone, security firm Forcepoint has published a report on the botnet's past operations.

The botnet exploited a single vulnerability

In those eight years, the Cereals botnet only exploited one vulnerability.

The vulnerability existed in the SMS notification of D-Link firmware, which powered the company's line of NAS and NVR devices.

The bug allowed the Cereals creator to send an HTTP request to a built-in server on a vulnerable device and execute commands with root privileges.

Forcepoint says the hacker had scanned the Internet for vulnerable D-Link systems, and exploited the flaw to install the Cereals malware on vulnerable NAS and NVR devices.

botnet

However, despite exploiting a single vulnerability, the botnet was quite advanced. Cereals had four backdoor mechanisms for gaining access to infected devices and attempted to patch systems to prevent compromise by other attackers.

Was it a…… hobby?

According to Forcepoint researchers, the botnet could be described more as a hobby project.

Initially, as we said above, it exploited only one vulnerability during its eight-year "life" and did not attempt to extend its functionality to other systems beyond D-Link NAS and NVRs.

The botnet never deviated from its purpose, which was to download Anime videos. Forcepoint said the botnet did not carry out DDoS attacks, nor did it attempt to access data user stored on NAS and NVR devices.

All of this suggests that the botnet's creator, believed to be a German man named Stefan, probably didn't intend to use the Cereals botnet for "evil purposes." His only goal was to download Anime videos.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS