HomeSecurityUpdated RapperBot malware targets game servers in DDoS attacks

Updated RapperBot malware targets game servers in DDoS attacks

The RapperBot botnet, which is based on Mirai, reappeared through a new campaign that infects IoT devices for DDoS (Distributed Denial of Service) attacks against game servers.

Last August, Fortinet researchers found malware that infected Linux servers via SSH brute-forcing.

Researchers found that RapperBot has been active since May 2021, but it is difficult to understand its specific targets.

See also: CISA: Iranian hackers breached organization with Log4Shell exploit

RapperBot

The newer version of this virus uses a Telnet self-propagation mechanism, which resembles the original malicious software Mirai more.

Also, the motivation of the current campaign is more apparent, as the DoS commands in the latest variant are tailored for attacks against servers hosting online games.

See also: Leader of JabberZeus hacking group arrested in Geneva

What exactly is RapperBot

Fortinet analysts were able to sample the new variant using C2 communication artifacts collected in previous campaigns, suggesting that this part of the botnet's operation remained unchanged.

The analysts discovered that the new variant included several changes, such as support for Telnet brute-forcing, via these commands:

  • Register (used by the client)
  • Stay idle/Do nothing
  • Stop all DoS attacks and terminate the client
  • Execute a DoS attack
  • Stop all DoS attacks
  • Restart the Telnet brute forcing
  • Stop the Telnet brute forcing

The malware attempts to gain access to devices using common weak credentials from a hardcoded list, instead of pulling the information from the C2 as it did in the past.

After successfully finding the credentials, it reports this to the C2 via port 5123 and then attempts to retrieve and install the correct version of the primary payload binary for the detected device architecture .

See also: CommonSpirit Health: Ransomware attack likely affects millions of Americans

Updated RapperBot malware targets game servers in DDoS attacks

It is likely that the same entities are involved

Fortinet discovered that all RapperBot campaigns are controlled by the same individuals, as newer variants show that they have access to the malware's source code

Moreover, the C2 communication protocol has not changed since August 2021 and the breach attempts have used the same credentials. Also, there is no evidence that different campaigns are collaborating at this time.

The best way to protect IoT devices from botnet infections is to keep the firmware up to date, change the default credentials to a difficult and unique password, and place them behind a firewall whenever possible.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS