HomeSecurityThe P2PInfect botnet is experiencing a period of high activity

The P2PInfect botnet is experiencing a period of high activity

The P2PInfect botnet worm has been experiencing a period of high activity since August and continues with even greater intensity in September 2023.

P2PInfect was first documented by Unit 42 in July 2023 as peer-to-peer malware that compromises Redis instances using a remote code execution vulnerability on internet-accessible Windows and Linux systems.

Cado security researchers, who have been monitoring the botnet since July 2023, are currently reporting global activity, with most breaches affecting systems in China, the United States, Germany, Singapore, Hong Kong, the United Kingdom , and Japan.

Furthermore, according to Cado, the latest P2PInfect samples include additions and improvements that make it more capable of spreading to targets and demonstrate the malware's continued development.

P2PInfect

Rapid increase in activity

Cado investigates the activity of the P2PInfect botnet, indicating that the malicious code has entered a new period of stability that allows it to strengthen its operation.

Researchers report that they are observing a steady increase in the number of initial access attempts that P2PInfect makes to their honeypots, leading to 4,064 incidents from a single sensor by August 24, 2023.

By September 3, 2023, initial access events had tripled, but remained relatively low.

Then, in the week between September 12th and 19th, 2023, there was a surge in P2PInfect activity, with Cado recording 3,619 access attempts during this period alone, showing a 600-fold increase.

New P2PInfect features

Along with the increased activity, Cado observed new patterns that make P2PInfect a more invisible and dangerous threat actor.

First, the malware's creators have added a cron-based persistence mechanism that replaces the previous 'bash_logout' method, triggering the main payloads every 30 minutes.

Additionally, P2Pinfect now uses a (secondary) bash payload to communicate with the main payload via a local server socket and, if the main process is stopped or deleted, it retrieves a copy from a user and restarts it.

The malware now also uses an SSH key to replace any SSH authorized_keys on the compromised endpoint to prevent legitimate users from connecting via SSH.

If the malware has root access, it will perform a password change for any other user on the system, using an automatically generated 10-character password to lock them out.

P2PInfect now uses a C structure for its client configuration, which is dynamically updated in memory, whereas previously it did not have a configuration file.

Unclear goals

According to Cado's report, the recently observed P2PInfect variants attempted to retrieve a miner payload, but no actual mining activity was observed on the compromised devices. Therefore, it is unclear whether the malware's creators are still experimenting with the final step of the attack.

The botnet operators may be upgrading the miner component or looking for subscription buyers for P2PInfect, so they can use the miner as a temporary solution for demonstration.

Considering its current size, prevalence, automatic update features, and rapid expansion this month, P2PInfect is a significant threat that we should monitor closely.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS