HomeSecurityDDoS malware Lucifer now targets Linux systems

Lucifer DDoS malware now targets Linux systems

A hybrid DDoS botnet known for turning vulnerable Windows devices into Monero cryptojacking bots is now scanning and infecting Linux systems. While the botnet's authors named it Satan DDoS, security researchers are calling it Lucifer to differentiate it from the Satan ransomware.

In addition to adding Linux targeting support, Lucifer's creators have also expanded the version to steal credentials and escalate privileges using the Mimikatz tool after a breach.

Lucifer DDoS malware

When first detected by Palo Alto Networks Unit 42 researchers in May, the malware deployed an XMRig miner on Windows computers that had been infected using weapons targeting high and critical vulnerabilities or by brute-forcing machines with open TCP ports 135 (RPC) and 1433 (MSSQL).

Similar features to the Windows version

As detailed in a report published today by researchers from NETSCOUT's ATLAS Security Engineering & Response (ASERT) team, the Linux port displays the same welcome message as the Windows variant.

The new Linux version has features similar to its Windows counterpart, including modules designed for encryption and for launching flooding attacks based on TCP, UCP, and ICMP.

Additionally, Linux devices infected with Lucifer can also be used in HTTP- (including HTTP GET- and POST-banjir and HTTP “CC” DDoS attacks).

The full list of DDoS attacks that can be carried out using Lucifer-infected devices is available in the table below.

Lucifer DDoS malware now targets Linux systems

Ever-dangerous cross-platform botnet

By adding support for additional platforms, Lucifer's authors ensure that they can expand the total number of devices controlled by their botnet.

This translates to much more cryptocurrency being mined by the botnet in the future – in May when it was first detected, Lucifer’s crypto wallets contained only $30 worth of Monero – as well as more dangerous DDoS attacks being carried out against potential targets.

"At first glance, a hybrid cryptojacker/DDoS bot seems a bit unusual. However, given the prevalence of DDoS attacks within the illicit cryptocurrency arena ,it is surprising to have a 'one-stop' bot," the researchers said.

“This allows controllers to fulfill their needs in one simple move rather than forcing them to use booter/stresser services or other DDoS botnets to thwart their adversaries’ progress.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS