HomeSecurityMatryosh botnet: Targets Android-based devices for DDoS attacks!

Matryosh botnet: Targets Android-based devices for DDoS attacks!

On January 25, 2021, 360 netlab researchers detected a suspicious ELF file , which they initially linked to the Mirai botnet. However, after further investigation, they concluded that this file was associated with a new botnet called “Matryosh”. Specifically, the researchers stated the following in their analysis: “On January 25, 2021, 360 netlab identified a suspicious ELF file as Mirai, but the network traffic did not match the characteristics of Mirai. This anomaly caught our attention and after analysis, we determined that it was a new botnet that reused the Mirai framework, spread via exposed Android Debug Bridge (ADB) interfaces, and targeted Android-based devices, with the primary goal of performing DDoS attacks.”

Android Debug Bridge (ADB) is a command-line tool that allows developers to communicate with an Android device. The ADB command facilitates a variety of device actions, such as installing and debugging applications, while also providing access to a Unix shell that you can use to run a variety of commands on a device.

Matryosh botnet: Targets Android-based devices for DDoS attacks!

ADB could be abused by malwareto target Android devices via port 5555. By default, Android has the Android Debug Bridge (ADB) option disabled. However, vendors often allow it to customize the operating system, thus infecting devices that have the feature enabled.

The Matryosh botnet, which targets Android-based devices for DDoS attacks, uses the network to evade detection. Furthermore, the researchers noted that the encryption algorithm used in this botnet and the C2 acquisition process are layered, like Russian nesting dolls. For this reason, they named the botnet “Matryosh.”

Matryosh botnet: Targets Android-based devices for DDoS attacks!

They also identified a similarity to the C2 instructions used by Moobot, which continues to be very active at this time.

As Security Affairs reports, the Matryosh botnet first decrypts the remote hostname and uses the DNS TXT request to obtain the TOR C2 and TOR proxy, and then connects to the TOR proxy. The botnet communicates with the TOR C2 through the proxy and waits for commands from the C&C server.

Matryosh botnet: Targets Android-based devices for DDoS attacks!

According to the researchers, Matryosh's cryptographic design has some innovation, but it still falls under the Mirai single-byte XOR pattern, which is why it is easily flagged by antivirus software as Mirai. The changes in the network communication layer suggest that its creators wanted to implement a mechanism to protect the C2 by downlinking the configuration from the cloud, which will bring some difficulties to static analysis or simple IOC simulator.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS