HomeSecurityHow does the new Zerobot malware work?

How does the new Zerobot malware work?

A new malware called “Zerobot” has been detected that uses exploits for nearly two dozen vulnerabilities in a variety of devices such as F5 BIG-IP and Zyxel firewalls, Totolink and D-Link routers, and Hikvision cameras.

See also: Crypto scam targets young Elon Musk followers on Twitter

Zerobot malware

The Zerobot malware works by adding infected devices to a distributed denial-of-service (DDoS) botnet, which can then be used to launch attacks against specific targets.

Zerobot can scan the network and spread itself to neighboring devices as well as execute commands on Windows (CMD) or Linux (Bash).

Fortinet security researchers discovered Zerobot in November. Since then, a new version has appeared with additional modules and exploits for new flaws, suggesting that the malware is still actively developing.

See also: Why are the holidays the best time for scammers?

The malware can attack a wide range of system architectures and devices. Here are some examples: i386, AMD64, ARM, ARM64, MIPS, MIPS64, MIPS64le, MIPSle, PPC64, PPC64le, RISC64, and S390x.

Zerobot uses 21 vulnerabilities to gain access to the device, and then downloads a script called “zero” that allows it to spread.

How does the new Zerobot malware work?

Zerobot uses the following exploits to gain access to its targets:

  • CVE-2014-08361: miniigd SOAP service in Realtek SDK
  • CVE-2017-17106: Zivif PR115-204-P-RS webcams
  • CVE-2017-17215: Huawei HG523 router
  • CVE-2018-12613: phpMyAdmin
  • CVE-2020-10987: Tenda AC15 AC1900 router
  • CVE-2020-25506: D-Link DNS-320 NAS
  • CVE-2021-35395: Realtek Jungle SDK
  • CVE-2021-36260: Hikvision product
  • CVE-2021-46422: Telesquare SDT-CW3B1 router
  • CVE-2022-01388: F5 BIG-IP
  • CVE-2022-22965: Spring MVC and Spring WebFlux (Spring4Shell)
  • CVE-2022-25075: TOTOLink A3000RU router
  • CVE-2022-26186: TOTOLink N600R router
  • CVE-2022-26210: TOTOLink A830R router
  • CVE-2022-30525: Zyxel USG Flex 100(W) firewall
  • CVE-2022-34538: MEGApix IP cameras
  • CVE-2022-37061: FLIX AX8 thermal sensor cameras

The botnet doesn't just use old exploits – it also exploits four that don't yet have CVE numbers. Two of them exploit vulnerabilities in GPON terminals and D-Link routers, but we don't know much about the other two yet.

How does the new Zerobot malware work?

Zerobot functions

After Zerobot infiltrates a device, it establishes a WebSocket connection with the command and control (C2) server. It then sends information about the victim back to the C2 server.

C2 can respond with any of the following commands:

  • ping – maintaining connection
  • attack – Launch attack for different protocols: TCP, UDP, TLS, HTTP, ICMP
  • stop – Stop the attack
  • update – Install the update and restart Zerobot
  • enable_scan – Scan for open ports and start propagation via exploit or SSH/Telnet cracker
  • disable_scan – Disable scanning
  • command – Execute the OS command, cmd on Windows and bash on Linux
  • kill – “Kill” the botnet

The malware also uses an “anti-kill” module designed to prevent the termination or “death” of process .

Currently, Zerobot is primarily focused on launching DDoS attacks, but it could also be used as an initial access point.

See also: Galaxy S22: Hacked twice on the first day of Pwn2Own

Fortinet says that since Zerobot first appeared on November 18, its developer has improved it with string obfuscation, a file copy module, a self-propagation module, and several new exploits.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS