HomeSecurityNew DDoS botnet AndoryuBot exploits a Ruckus RCE bug

New DDoS botnet AndoryuBot exploits a Ruckus RCE bug

A new malware botnet, dubbed “AndoryuBot,” targets a critical vulnerability in Ruckus Wireless’ Admin panel to infect unpatched Wi-Fi access points for use in DDoS attacks.

The flaw is identified as CVE-2023-25717 and affects all versions 10.4 and earlier of Ruckus Wireless Admin panels, allowing remote attackers to execute code by sending unauthorized HTTP GET requests to vulnerable devices.

The flaw was discovered and patched on February 8, 2023. However, many have not applied the available security updates, while end-of-life models affected by the security issue will not receive a fix.

AndoryuBot first appeared in February 2023, but Fortinet says the newer version targeting Ruckus devices appeared in mid-April.

The botnet malware aims to recruit vulnerable devices into the DDoS (distributed denial of service) swarm it manages for profit.

See also: Magecart malware strikes e-commerce websites again and again

AndoryuBot

See also: Efforts to stop ransomware are starting to bear fruit

Ruckus attack details

The malware infects vulnerable devices via malicious HTTP GET requests and then downloads an additional script from a hardcoded URL for further propagation.

New DDoS botnet AndoryuBot exploits a Ruckus RCE bug

The variant analyzed by Fortinet can target multiple system architectures, including x86, arm, spc, m68k, mips, sh4, and mpsl.

After infecting a device, the malware establishes communication with the C2 server using the SOCKS proxying protocol for stealth and bypassing firewalls, and then waits for commands.

New DDoS botnet AndoryuBot exploits a Ruckus RCE bug

AndoryuBot project

The AndoryuBot malware supports twelve DDoS attack modes: TCP-raw, TCP-socket, TCP-CNC, TCP-handshake, UDP-plain, UDP-game, UDP-OVH, UDP-raw, UDP-VSE, UDP-dstat, UDP-bypass, and ICMP-echo.

New DDoS botnet AndoryuBot exploits a Ruckus RCE bug

The malware will receive commands from the command and control server that will tell it the type of DDoS, the target IP address, and the port number for the attack.

Malware administrators rent out their firepower to other cybercriminals who want to launch DDoS, accepting payments in cryptocurrencies (XMR, BTC, ETH, USDT, CashApp) in exchange for their services.

Fortinet says weekly rental rates range from $20 for a single-login, 90-second attack using all available bots launched 50 times per day to $115 for a dual-login, 200-second attack using all available bots to launch 100 attacks per day.

See also: Sysco confirms its network was breached

The Andoryu Project is currently being promoted through YouTube videos, in which its operators demonstrate the botnet's capabilities.

AndoryuBot

To prevent botnet malware infections, apply available firmware updates, use strong device administrator passwords, and disable remote access to the management panel if it is not necessary.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS