HomeSecurityGorillaBot has emerged as the "king" of DDoS attacks

GorillaBot has emerged as the "king" of DDoS attacks

A DDoS attack aims to disrupt the normal operation of a server, service, or network by flooding it with excessive internet traffic.

Gorillabot

This attack is carried out through a network of compromised devices, known as a botnet, which sends countless requests to the target, effectively limiting its bandwidth and resources.

Recently, NSFocus analysts identified a botnet that stands out as a top DDoS attack botnet, with more than 300,000 commands, and it was named “GorillaBot“.

Read more: Fake CAPTCHA requests contain malware

GorillaBot has emerged as the "king" of DDoS attacks

In September 2024, the Gorilla Botnet, a variant of the Mirai malware, launched an unprecedented cyberattack campaign. Over a 24-day period, it carried out more than 300,000 DDoS attack targeting 113 countries, with the following being most affected:

  • China (20%)
  • United States (19%)
  • Canada (16%)
  • Germany (6%)

This botnet supports most major CPU architectures, such as ARM, MIPS, x86_64, and x86. In addition, it used various attack methods, such as “UDP Flood (41%)”, “ACK BYPASS Flood (24%)”, and “VSE Flood (12%)”.

The Gorilla Botnet targeted various sectors, including universities, government websites, telecommunications, banks, and gaming platforms. It implemented encryption associated with the KekSec group to hide critical information and used multiple techniques to maintain long-term control over IoT devices and cloud computing centers.

See also: Emerging threats to cloud security

The botnet's infrastructure includes five embedded C&C servers, randomly selected for connections. Its arsenal includes 19 different attack vectors, indicating a sophisticated strategy, according to NSFocus.

This emerging threat features advanced anti-detection capabilities and highlights the “evolving threat.” It exploits an unauthorized access through the “Hadoop Yarn RPC” function, specifically through the “yarn_init” function, potentially granting elevated privileges to hackers.

GorillaBot creates multiple system files and scripts for persistent presence. Here are some of them:

  • A “custom.service” file in /etc/systemd/system/ for automatic startup.
  • Modifications to /etc/inittab and /etc/profile.
  • The /boot/bootcmd file is executed during system startup or user login.
  • A “mybinary” script in /etc/init.d/ with a link to /etc/rc.d/rc.local or /etc/rc.conf.
DDoS

See also: US says Chinese Botnet compromises 260,000 SOHO devices

These mechanisms ensure the automatic download and execution of a malicious script named “lol.sh” from http[:]//pen.gorillafirewall.su/. In addition, the malware includes “anti-honeypot measures,” checking the existence of the “/proc” file system to detect potential security traps.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

GorillaBot's use of specific encryption methods, the script name "lol.sh", as well as certain code signatures, suggest a possible connection to "KekSec".

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS