Protect your Linux servers from XorDdos, a botnet that scans the Internet for SSH servers with weak passwords, Microsoft warns.

See also: BPFdoor: Linux malware bypasses firewalls for remote access
Microsoft has seen a 254% increase in activity in recent months from XorDDoS, a network of infected Linux machines about eight years old that is used for denial of service (DDoS) attacks.
XorDdos performs automated password-guessing attacks on thousands of Linux servers to find the corresponding admin credentials used on Secure Shell (SSH) servers. SSH is a secure network communications protocol commonly used for remote system administration.
Once the credentials are obtained , the botnet uses root privileges to install itself on a Linux device and uses XOR-based encryption to communicate with the attacker 's command and control infrastructure .
While DDoS attacks pose a serious threat to system availability and are growing in size every year, Microsoft is concerned about other capabilities of these botnets.
"We found that devices initially infected with XorDdos were later infected with additional malware, such as the Tsunami backdoor, which further deploys the XMRig coin miner," Microsoft notes.
XorDDoS was one of the most active Linux-based malware families of 2021, according to Crowdstrike. The malware has thrived on the development of Internet of Things (IoT), which mostly run on Linux variants, but has also targeted misconfigured Docker clusters in the cloud. Other top malware families targeting IoT devices include Mirai and Mozi.
See also: Nimbuspwn Linux vulnerability gives hackers root privileges
Microsoft did not see XorDdos directly installing and distributing the Tsunami backdoor, but its researchers believe that XorDdos is being used as a vector for subsequent malicious activities.
XorDdos can hide its activities from common detection techniques. In a recent campaign, Microsoft saw it replace sensitive files with a null byte.

The XorDdos payload that Microsoft analyzed is a 32-bit Linux format ELF file with a modular binary written in C/C++. Microsoft notes that XorDdos uses a process that runs in the background, outside of user control, and terminates when the system shuts down.
However, the malware can be restarted automatically upon a system reboot, thanks to several scripts and commands that cause it to run automatically upon system startup.
XorDdoS can perform many DDoS, including SYN flood attacks, DNS , and ACK flood attacks.
See also: Serious vulnerability found in Linux IPsec – and fixed
It collects characteristics about an infected device, such as the magic string, operating system version , malware version, rootkit presence, memory statistics, CPU information, and LAN speed , which are encrypted and then sent to the C2 server .
The huge boost in XorDDoS activity that Microsoft detected since December is consistent with a report by cybersecurity firm CrowdStrike, which said Linux malware had seen a 35% increase in 2021 compared to the previous year.
Information source: zdnet.com
