HomeSecurityIPStorm botnet expands from Windows to Android, Mac and Linux

IPStorm botnet expands from Windows to Android, Mac and Linux

IPStorm, a malware botnet first detected last year targeting Windows systems, has evolved to infect other types of platforms, including Android, Linux, and Mac devices.

Furthermore, the botnet has also quadrupled in size, from 3,000 infected systems in May 2019 to more than 13,500 devices this month.

These latest developments place IPStorm in the category of the most dangerous botnets today, which is logical since it is constantly developing.

Android Mac Linux botnet IPStorm windows

His story

IPStorm, first detected in May 2019 and described in an Anomali report in June 2019, began operating by targeting only Windows systems.

At the time of its discovery, security researchers identified several unique features of IPStorm. For example, the full name of the InterPlanetary Storm malware came from the InterPlanetary File System (IPFS), a peer-to-peer protocol that the malware used to communicate with infected systems.

Second, the malware was also written in the Go programming language. While Go malware has become common today, it was not as common in 2019, making IPStorm one of the few malware strains of its kind.

However, Anomali's 2019 report never explained how the malware spread to infect Windows systems.

The two security companies (Bitefender and Barracuda) released two reports and stated that they have identified some new versions of IPStorm that are capable of infecting devices running other platforms beyond Windows, such as Android, Linux, and Mac.

And this time, there is also information about how the botnet is spreading, effectively dispelling the idea that it was just an experiment and confirming that it is a well-organized attack that keeps the botnet alive.

According to Bitdefender and Barracuda, IPStorm targets and infects Android systems by scanning the internet for devices that had left the ADB (Android Debug Bridge) port exposed.

On the other hand, Linux and Mac devices are infected when the IPStorm gang performs attacks against SSH services to guess usernames and passwords.

After IPStorm gains an initial foothold on these systems, the malware typically checks for the presence of honeypot software, acquires “boot persistence” on the device, and then kills a list of processes that may pose a threat to its operations.

The ultimate goal of IPStorm remains unknown

Nevertheless, despite being active for more than a year, security researchers have yet to figure out one last thing about IPStorm, its ultimate goal.

Security researchers say that IPStorm drops a reverse shell on all infected devices, but then does not bother those systems.

While this backdoor could be used in an unlimited manner, so far, security researchers have not seen IPStorm operators doing anything malicious, such as installing crypto-mining, performing DDoS attacks , or relaying malicious traffic as part of a proxy network.

This remains a mystery that security researchers are still investigating, but it likely won't be a positive thing for infected systems and their owners.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS