HomeSecurityCatDDoS botnet: Increased infections to carry out DDoS attacks

CatDDoS botnet: Increased infections to carry out DDoS attacks

Researchers have discovered that, over the past three months, hackers behind the CatDDoS botnet have exploited over 80 vulnerabilities in various software to infiltrate vulnerable devices and include them in the botnet to carry out DDoS attacks.

CatDDoS botnet DDoS

According to the QiAnXin XLab, the maximum number of targets exceeds 300+ per day.

The vulnerabilities exploited by hackers affect routers, networking equipment and other devices from vendors such as Apache (ActiveMQ, Hadoop, Log4j and RocketMQ), Cacti, Cisco, D-Link, DrayTek, FreePBX, GitLab, Gocloud, Huawei, Jenkins, Linksys, Metabase, NETGEAR, Realtek, Seagate, SonicWall, Tenda, TOTOLINK, TP-Link, ZTE, Zyxel and others.

See also: Ebury malware botnet has infected 400,000 Linux servers

The CatDDoS botnet was analyzed in late 2023 and was presented as a variant of the well-known Mirai botnet, which could perform attacks using UDP, TCP, and other methods.

It first appeared in August 2023 and was named CatDDoS due to references to cats within the strings for command-and-control (C2) domains (e.g. “catddos.pirate” and “password_meow”).

Most of the CatDDoS botnet's targets are located in China, followed by the US, Japan, Singapore, France, Canada, the UK, Bulgaria, Germany, the Netherlands and India.

Its operators try to avoid detection by using various methods, such as the ChaCha20 to encrypt communications with the C2 server, using an OpenNIC domain for the C2, and more.

See also: Phorpiex botnet sent millions of emails distributing LockBit Black ransomware

It is worth noting that CatDDoS also shares the same key/nonce pair for the ChaCha20 algorithm with three other DDoS botnets named hailBot, VapeBot, and Woodman.

XLab said the new attacks are mainly focused on countries such as the US, France, Germany, Brazil and China and target cloud service providers and sectors such as education, scientific research, information transmission, public administration, construction and other industries.

It is suspected that the original creators behind the malware ceased their activities in December 2023, but put the source code up for sale in a Telegram group.

“ Due to the sale or leakage of source code, new variants emerged, such as RebirthLTD, Komaru, Cecilio Network, etc. after the shutdown ,” the researchers said . “ Although different variants may be managed by different teams, there is little differentiation in the code, communication design, strings, decryption methods, etc. ”

See also: Ivanti vulnerabilities used to deploy Mirai botnet

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CatDDoS botnet: Increased infections to carry out DDoS attacks

Protection against botnet malware

To protect yourself from CatDDoS and other Botnets, it is important to keep your device's software and operating system up to date. Botnet attacks often exploit known vulnerabilities.

Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

Using strong passwords and changing them regularly is another way to protect yourself from Botnet (e.g. CatDDoS). Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect your accounts.

Finally, information security training can be particularly useful. Understanding how attacks work and the techniques they use can help you identify and avoid attacks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS