The FritzFrog botnet, which has been active for more than two years, has resurfaced with an alarming infection rate, increasing tenfold in just a month, hitting healthcare, education, and government systems with an exposed SSH server.
See also: Mirai botnets exploit lax IoT security

The malware analyzed in August 2020 is written in Golang and is considered a sophisticated threat that is based on custom code, runs in memory, and is decentralized — peer-to-peer (P2P), so it does not require a central management server.
Akamai researchers have identified a new version of the FritzFrog malware, which comes with interesting new features, such as the use of the Tor proxy chain.
The new variant also indicates that its operators are preparing to add capabilities to target WordPress servers.
Akamai calls the FritzFrog botnet a "next-generation" one because it combines features that make it stand out from other threats in the same category.
See also: Phorpiex botnet: New Twizt variant makes it easier to steal cryptocurrencies
The malware is better equipped to evade detection and maintain a low profile due to its use of a “completely proprietary” P2P protocol for communications.
It relies on an extensive dictionary of brute-force attacks to find SSH credentials, which allows it to compromise a larger number of devices.
Second wave with new abilities
Akamai's global sensor network has detected 24,000 attacks, but the botnet has only had 1,500 victims so far. Most of the infected hosts are in China, but among the compromised systems are a European television network, a Russian healthcare company, and several universities in East Asia.

It also appears that the malware now contains code that lays the groundwork for targeting WordPress websites.

Considering that the botnet is known for mining cryptocurrency, this feature is an odd addition. However, Akamai assumes that the hackers have found other ways to generate revenue, such as deploying ransomware or data leaks. Currently, this feature is inactive as it is being worked on.
The researchers note that FritzFrog is constantly under development, with bugs being fixed on a daily basis, sometimes multiple times a day.
Another innovation in the latest FritzFrog sample is proxying outgoing SSH connections through Tor, hiding the network structure and limiting visibility from infected nodes in the botnet. While this feature seems complete, the developers have not yet enabled it.
Finally, the copying system (used to infect new systems) is now based on SCP ( security copy protocol ), replacing the cat command that was present in the previous version.
See also: Dark Mirai botnet targets popular TP-Link router with RCE
At this time, Akamai researchers are not definitively certain of the responsibility for the FritzFrog operation, but evidence points to China.
FritzFrog targets any device that exposes an SSH server, so administrators of data center servers, cloud instances, and routers should remain vigilant.
Information source: bleepingcomputer.com
