An advanced botnet campaign named FritzFrog was found to be compromising SSH servers worldwide, at least since January 2020.
Written in Golang, FritzFrog is a worm and a botnet that targets the sectors of government, education, and finance.

The attack has already managed to infiltrate over 500 servers in the US and Europe, universities and railway companies.
The advanced nature of FritzFrog lies in its proprietary and anonymous P2P application that is written from scratch.
Without files, without servers but also so effective
The malware gathers and executes the malicious payload in memory, making it unstable.
Furthermore, the custom P2P application means that there is no Command & Control server (C&C) sending instructions to FritzFrog.
Despite the aggressive brute-force tactics that FritzFrog uses to breach SSH servers, it is strangely effective at targeting a network uniformly.
Guardicore Labs has been monitoring FritzFrog for the past months using a honeypot network.
“We began monitoring the campaign activity, which steadily and significantly increased over time, reaching a total of 13 thousand attacks on the Guardicore Global Sensors Network (GGSN). Since its first appearance, we have detected 20 different versions of the Fritzfrog binary,” the company states in a recently published report written by security researcher Ophir Harpaz.
In their attempt to locate a central C&C design that feeds the botnet, the company soon realized that there was nothing like that.
To better understand FritzFrog and its capabilities, Guardicore Labs designed an interceptor written in Golang called frogger, which could participate in the malware key exchange process and receive and send commands.
“This program, which we called frogger, allowed us to explore the nature and scope of the network. Using frogger, we were also able to join the network” by inserting “our own nodes and participating in the current P2P traffic,” the report states.
Thus, Guardicore Labs concluded that the malware campaign had brute-forced access to millions of SSH IP addresses belonging to institutions such as medical centers, banks, telecommunications companies, educational and government organizations.
When analyzed by the researchers at Guardicore Labs, the malware is unique given its distributed nature. While other botnets such as IRCflu have used IRC or, like DDG, have operated using files, FritzFrog exhibits none of these behaviors.
The report acknowledges, however, “It bears some similarity – especially in terms of function naming and version numbers – to Rakos, a P2P botnet written in Golang and analyzed by ESET in 2016.” Guardicore Labs has provided a simple script that can be used to detect FritzFrog infections. Both the script and a list of FritzFrog IoCs have been published on GitHub.
“FritzFrog exploits the fact that many network security solutions enforce traffic only by port and protocol. To overcome this stealth technique, process-based segmentation rules can easily prevent such threats,” their report concludes.
