HomeSecurityNew DDoS botnet campaign targets IoT devices

New DDoS botnet campaign targets IoT devices

A hacker, going by the name Matrix, has been linked to a widespread distributed denial-of-service (DDoS) campaign that exploits vulnerabilities and misconfigurations in Internet of Things (IoT) devices to integrate them into a destructive botnet.

DDoS botnet IoT devices

There is evidence to suggest that the attacks may be the work of a single individual of Russian origin. The attacks primarily targeted IP addresses in China, Japan, and to a lesser extent Argentina, Australia, Brazil, Egypt, India, and the United States.

According to cloud security company Aqua, the absence of Ukraine among the victims indicates that the motives are purely financial.

See also: Ngioweb botnet blocked by authorities

Attack chains are characterized by the exploitation of known vulnerabilities as well as default or weak credentials to gain access to a wide range of internet-connected devices (e.g. IP cameras, DVRs, routers, and telecommunications equipment).

Additionally, the attacker exploits misconfigurations in Telnet, SSH, and Hadoop servers, with a particular focus on targeting IP address ranges associated with cloud service providers (CSPs) such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud.

Researchers have observed that the malicious activity is also based on a wide range of publicly available scripts and tools available on GitHub. Ultimately, the Mirai botnet malware on compromised devices and servers, as well as other programs related to DDoS attacks. For example, PYbot, pynet, DiscordGo, Homo Network, a JavaScript program that implements an HTTP/HTTPS flood attack, and a tool that can disable Microsoft Defender Antivirus on Windows computers are used.

See also: Botnet exploits zero-day vulnerability in GeoVision

Matrix was also found to be using his own GitHub account, opened in November 2023, to organize certain DDoS artifacts.

Researchers also believe that this is all being advertised as a DDoS-for-hire via a Telegram bot called “Kraken Autobuy.”

Matrix

“This campaign, while not particularly sophisticated, demonstrates how publicly available tools and basic technical knowledge can allow individuals to execute a broad, multi-faceted attack on network-connected devices,” said a researcher.

Botnet protection

To protect against this threat, it is important to software and operating system your device's. Botnet attacks often exploit known vulnerabilities.

It is also essential to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

See also: Chinese hackers Volt Typhoon “rebuild” the KV-Botnet

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Using strong passwords and changing them regularly is another way to protect yourself from Botnets. Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect your accounts.

Finally, information security training can be particularly useful. Understanding how botnet attacks work can help you identify and avoid attacks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS