A new malware botnet, dubbed “AndoryuBot,” targets a critical vulnerability in Ruckus Wireless’ Admin panel to infect unpatched Wi-Fi access points for use in DDoS attacks.
The flaw is identified as CVE-2023-25717 and affects all versions 10.4 and earlier of Ruckus Wireless Admin panels, allowing remote attackers to execute code by sending unauthorized HTTP GET requests to vulnerable devices.
The flaw was discovered and patched on February 8, 2023. However, many have not applied the available security updates, while end-of-life models affected by the security issue will not receive a fix.
AndoryuBot first appeared in February 2023, but Fortinet says the newer version targeting Ruckus devices appeared in mid-April.
The botnet malware aims to recruit vulnerable devices into the DDoS (distributed denial of service) swarm it manages for profit.
See also: Magecart malware strikes e-commerce websites again and again

See also: Efforts to stop ransomware are starting to bear fruit
Ruckus attack details
The malware infects vulnerable devices via malicious HTTP GET requests and then downloads an additional script from a hardcoded URL for further propagation.

The variant analyzed by Fortinet can target multiple system architectures, including x86, arm, spc, m68k, mips, sh4, and mpsl.
After infecting a device, the malware establishes communication with the C2 server using the SOCKS proxying protocol for stealth and bypassing firewalls, and then waits for commands.

AndoryuBot project
The AndoryuBot malware supports twelve DDoS attack modes: TCP-raw, TCP-socket, TCP-CNC, TCP-handshake, UDP-plain, UDP-game, UDP-OVH, UDP-raw, UDP-VSE, UDP-dstat, UDP-bypass, and ICMP-echo.

The malware will receive commands from the command and control server that will tell it the type of DDoS, the target IP address, and the port number for the attack.
Malware administrators rent out their firepower to other cybercriminals who want to launch DDoS, accepting payments in cryptocurrencies (XMR, BTC, ETH, USDT, CashApp) in exchange for their services.
Fortinet says weekly rental rates range from $20 for a single-login, 90-second attack using all available bots launched 50 times per day to $115 for a dual-login, 200-second attack using all available bots to launch 100 attacks per day.
See also: Sysco confirms its network was breached
The Andoryu Project is currently being promoted through YouTube videos, in which its operators demonstrate the botnet's capabilities.

To prevent botnet malware infections, apply available firmware updates, use strong device administrator passwords, and disable remote access to the management panel if it is not necessary.
Information source: bleepingcomputer.com
