HomeSecurityNew HinataBot botnet could launch massive DDoS attacks

New HinataBot botnet could launch massive DDoS attacks

The recently discovered HinataBot botnet has the ability to launch unprecedentedly powerful DDoS attacks of up to 3.3 Tbps, posing a significant threat to the security of companies and individuals around the world.

HinataBot

A new malware botnet, HinataBot, targets Realtek SDK, Huawei routers, and Hadoop YARN servers to recruit devices into a DDoS (distributed denial of service) swarm with the potential for mass attacks.

The new botnet was discovered by researchers at Akamai earlier this year, who caught it in their HTTP and SSH honeypots, while also seeing it exploit old flaws like CVE-2014-8361 and CVE-2017-17215.

Akamai reports that HinataBot distributors first released Mirai binaries and HinataBot was created in mid-January 2023. It appears to be derived from Mirai and is a Go of the known strain.

After collecting multiple samples from ongoing campaigns as recently as March 2023, Akamai researchers found that the malware continues to evolve and now features improved functionality and anti-analysis features.

New HinataBot botnet could launch massive DDoS attacks

Significant DDoS power

The malware spreads by compromising SSH endpoints or via malicious scripts and RCE payloads for known vulnerabilities.

Once the malware infiltrates a device, it will remain dormant until it receives instructions from the command and control server.

Akamai security experts built their own C2 and interacted with artificial infections to set up HinataBot for DDoS attacks, thus allowing them to observe the malware in action and infer its attack capabilities.

Although previous versions of HinataBot supported HTTP, UDP, ICMP, and TCP floods simultaneously, more recent models only feature two attack methods. Despite this limitation in capabilities, however, these botnets are still capable of producing extremely powerful distributed denial of service attacks.

New HinataBot botnet could launch massive DDoS attacks

Although the HTTP and UDP attack commands differ, both create a worker pool consisting of 512 processes which transmit predefined data packets to targets for a specified period.

The size of HTTP packets typically varies from 484 to 589 bytes. In contrast, the UDP packets produced by HinataBot are incredibly large – up to 65,549 bytes! These data-filled packets consist of zero bytes that can quickly overwhelm the target with a powerful flood of traffic.

HinataBot

HTTP floods send a massive volume of website requests, while UDP floods launch a series of useless traffic at the target. Despite using different methods, both approaches attempt to cause a service disruption

Akamai conducted 10-second botnet tests over HTTP and UDP, measuring 20,430 requests of 3.4 MB in the former case and 6,733 packets of 421 MB in the latter. The results were remarkable – the malware had a tenfold impact on data volume with UDP floods compared to its impact via HTTP requests!

The researchers calculated that with 1,000 nodes, the UDP flood could generate approximately 336 Gbps, while at 10,000 nodes, the attack data volume would reach 3.3 Tbps.

In the case of an HTTP flood, 1,000 devices can generate 2 million requests per second. Meanwhile, 10,000 nodes could generate up to 20.4 million requests per second and 27 Gbps of traffic!

As HinataBot is a work in progress, it is likely to incorporate further exploits and expand scope of targeting in the near future. Furthermore, with such active progress being made on this botnet, we should expect to see more powerful versions released soon.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS