HomeSecurityZerobot malware now spreads by exploiting Apache vulnerabilities

Zerobot malware now spreads by exploiting Apache vulnerabilities

The Zerobot botnet has been updated to exploit unpatched security vulnerabilities in Apache servers, allowing it to infect even more devices.

Zerobot

The Microsoft Defender for IoT research team also observed that this recent release implemented additional distributed denial-of-service (DDoS) capabilities.

See also: Play ransomware: Exploited Microsoft Exchange exploit

Zerobot has been under active development since at least November, with new releases adding new modules and capabilities to expand the botnet's attack vectors and make it easier to infect new devices, including firewalls, routers , and cameras.

Starting in early December, malware authors removed modules running on phpMyAdmin servers and Dasan GPON home routers, as well as D-Link DSL-2750B wireless routers, exploiting year-old vulnerabilities.

Microsoft has revealed a new update to its malware toolkit that gives it even more weapons. Hackers can target seven new types of devices and software, including unpatched Apache and Apache Spark servers.

See also: The Guardian: Is the British newspaper a victim of a ransomware attack?

Zerobot 1.1 includes an impressive array of modules, including the following:

  • CVE-2017-17105: Zivif PR115-204-P-RS
  • CVE-2019-10655: Grandstream
  • CVE-2020-25223: WebAdmin of Sophos SG UTM
  • CVE-2021-42013: Apache
  • CVE-2022-31137: Roxy-WI
  • CVE-2022-33891: Apache Spark
  • ZSL-2022-5717: MiniDVBLinux

Finally, the upgraded malware now has seven advanced DDoS capabilities, including an innovative TCP_XMAS attack technique.

Zerobot malware now spreads by exploiting Apache vulnerabilities

This malware created using the Go was named ZeroStresser by its creators and was detected in mid-November.

At the time of its discovery, this malware was using about two dozen exploits to target devices such as F5 BIG-IP, Zyxel firewalls, Totolink routers, D-Link cameras, and Hikvision.

From i386 to AMD64, ARM and ARM64 to MIPS, MIPSle and PPC64, RISC64 and S390x – this system is designed for a wide range of architectures and devices.

Zerobot spreads through brute force attacks against vulnerable devices with default or weak credentials and exploits vulnerabilities in Internet of Things (IoT) devices and web applications.

See also: Okta – source code: Stolen from GitHub repositories

Once a system is infected, it downloads a script called “zero” that allows the virus to spread and target other vulnerable devices available on the internet.

The botnet ensures persistence of the infiltrating gadgets, proving to be a powerful tool for executing large-scale DDoS attacks via various protocols.

As for the Apache server, it remains one of the most popular web servers available today due to its reliability, scalability, cost-effectiveness, and ability to deliver dynamic content quickly and easily.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS