HomeSecurityXORDDoS & Kaiji DDoS botnets: Targeting exposed Docker servers!

XORDDoS & Kaiji DDoS botnets: Targeting exposed Docker servers!

Researchers at cybersecurity firm Trend Micro reported that the operators behind the XORDDoS and Kaiji DDoS botnets have recently begun targeting Docker servers exposed to the Internet. The XORDDoS botnet, also known as XOR.DDoS, first appeared in 2014. It is a Linux botnet that has been used to attack educational and gaming sites, with massive DDoS attacks reaching 150 gigabytes of malicious traffic per second. The Kaiji botnet was discovered about two months ago by security research group MalwareMustDie and experts at Intezer Labs and targets Linux-based IoT devices via SSH brute-force attacks. According to experts, both botnets are linked to China, while their variants recently detected by Trend Micro have recently targeted Docker servers. Specifically, Trend Micro researchers reported that they have identified variants of two existing types of Linux botnet malware targeting exposed Docker servers: the XORDDoS malware, identified as Backdoor.Linux.XORDDOS.AE, and the Kaiji DDoS malware, identified as DDoS.Linux.KAIJI.A.

botnets-Docker servers

Botnet operators are looking for Docker servers whose port 2375 is exposed. This is one of the two ports in the Docker API and is used for unauthorized and unencrypted communications. Experts pointed out that there is a difference between the attack methods implemented by the two malware variants. Specifically, while the XORDDoS botnet infects all containers hosted on the Docker server, the Kaiji botnet deploys the DDoS malware in its own container. Furthermore, after compromising a Docker server, XORDDoS executes a sequence of commands to locate containers and infect them with the DDoS malware. The malware can also collect information about the compromised system as well as download and execute other payloads. While investigating the URL associated with the attacker, experts discovered other malware, such as Backdoor.Linux.DOFLOO.AB, that targets Docker containers. The Kaiji botnet operators scour the Internet for exposed Docker servers and deploy an ARM container that executes binary . Researchers discovered that the operators leverage a script to download and execute the main payload and to remove Linux binaries that are essential components of the operating system but not essential for its DDoS operation. The Kaiji botnet can also collect information about the compromised system and launch various types of DDoS attacks, including ACK, IPS spoof, SSH, SYN, SYNACK, TCP, and UDP attacks.

Trend Micro recommends the following for Docker server security:

  • Follow recommended best practices.
  • Use security tools to scan and secure containers.
  • Secure the container host. Take advantage of monitoring tools and “host” the container on a container-focused operating system.
  • Secure your networking environment. Use intrusion prevention system (IPS) and Internet filtering to provide visibility and monitor internal and external traffic.
  • Secure the management stack. Monitor and secure the container registry and lock down the Kubernetes installation
  • Secure your build pipeline. Implement a comprehensive access control scheme and install strong endpoint controls.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS