Cybersecurity researchers have discovered a new botnet named Zergeca , which, among other things, carries out distributed denial-of-service (DDoS) attacks

According to QiAnXin XLab, Zergeca is not just a typical DDoS botnet; it supports six different attack methods and includes capabilities for proxying, scanning, self-upgrading, persistence, file, reverse shell, and sensitive information collection.
See also: Botnet exploits vulnerability in Zyxel NAS devices
The Zergeca botnet also uses DNS-over-HTTPS (DoH) to perform Domain Name System (DNS) resolution of the C2 server and makes use of a lesser-known library, Smux, for C2 communications.
Researchers believe that the malware is evolving to support new commands. Additionally, it is said that the C2 IP address 84.54.51[.]82 was previously used to distribute the Mirai botnet, around September 2023. Since April, the same IP address has been used as a C2 server for the new Zergeca botnet.
From early to mid-June, the attacks (ACK flood DDoS) carried out by the botnet mainly targeted Canada, Germany, and the US.
See also: P2PInfect botnet: Targets Redis servers with new ransomware and cryptominer modules
The capabilities of the Zergeca botnet span four distinct modules: persistence, proxy, silivaccine, and zombie. The first module deals with maintaining persistence, the second with proxying, the third with removing competing malware and backdoors , and gaining control of devices running the x86-64 CPU architecture. Finally, the fourth handles the main functionality of the botnet.
The zombie module is responsible for reporting sensitive information from the compromised device to the C2 and awaits commands from the server. It supports six types of DDoS attacks, scanning, reverse shell and other functions.
See also: Muhstik botnet exploits vulnerability in Apache RocketMQ

Protection against botnet malware
To protect yourself from Zergeca and other Botnets, it is important to keep software and operating system up to date. Botnet attacks often exploit known vulnerabilities.
Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.
Using strong passwords and changing them regularly is another way to protect yourself from Botnets (e.g. Zergeca). Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect accounts .
Finally, information security training can be particularly useful. Understanding how botnet attacks work and the techniques they use can help you identify and avoid attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
