The attackers behind the peer-to-peer (P2P) botnet FritzFrog are back with a new variant that exploits the Log4Shell vulnerability to spread across an already compromised network.

According to security firm Akamai, the vulnerability is being used in a brute-force that attempts to target as many vulnerable Java applications as possible.
The FritzFrog botnet was first analyzed by Guardicore (now part of Akamai) in August 2020. It is a Golang-based malware that primarily targets internet-facing servers with weak SSH credentials.
Since 2020, the botnet malware has evolved to target healthcare, education , and government sectors. It has also acquired new capabilities, including one that enables crypto mining.
See also: Bigpanzi hackers: Their botnet targets Android TV boxes
Also, exploitation of the Log4Shell vulnerability is a feature of the new version of the botnet.
"When the vulnerability was first discovered, internet-facing applications had to be patched immediately due to the significant risk compromise of their," said a security researcher.
“Instead, the internal machines, which were less likely to be compromised, were neglected and left without repair — something that FritzFrog is now exploiting“.
So even if internet-facing applications have been patched, a breach of any other endpoint can expose unpatched internal systems to risk and allow botnet malware to spread.
The SSH brute-force component of the FritzFrog botnet has also received an update to detect specific SSH targets.
Another notable change in the malware is the use of the PwnKit vulnerability tracked as CVE-2021-4034 to gain more privileges on vulnerable systems.
See also: AndroxGh0st malware botnet steals AWS, Azure, Office 365 credentials
“FritzFrog continues to use tactics to remain hidden and avoid detection,” the researcher said. “In particular, special care is needed to avoid installing files to the disk when possible.”

Protection against botnet malware
To protect yourself from the FritzFrog Botnet, it is important to keep your device's software and operating system up to date. attacks exploit known vulnerabilities that have been patched in more recent versions of the software (as is the case in this case).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.
Using strong passwords and changing them regularly is another way to protect yourself from the FritzFrog Botnet. Botnet attacks often try to guess passwords ,so using strong passwords and changing them regularly can help protect your accounts.
See also: Increased botnet activity in the last month
Finally, security training can be particularly useful. Understanding how botnet attacks work and the techniques they use can help you identify and avoid attacks.
source: thehackernews.com
