HomeSecurityOver 4,000 ISP IPs Targeted in Brute-Force Attacks

Over 4,000 ISP IPs Targeted in Brute-Force Attacks

Internet service providers (ISPs) in China and the West Coast of the United States have been targeted by a Brute-Force campaign that deploys infostealers and cryptominers on compromised servers.

See also: Brute-force attacks target Citrix NetScaler appliances

ISP Brute Force

The findings come from Splunk Threat Research , which said the activity also led to the delivery of various binaries that facilitate data infiltration and offer ways to establish persistence on systems .

The unknown malicious actors performed " minimal intrusive actions to avoid detection, with the exception of artifacts created from accounts that had already been compromised ," the Cisco-owned company said in a technical report published last week

The attacks have been observed to utilize Brute-Force attacks that exploit weak credentials. These intrusion attempts originate from IP addresses associated with Eastern Europe. More than 4,000 ISP IP addresses are said to have been targeted by these Brute-Force attacks.

See also: Cisco patches vulnerability that allows Brute-Force

After gaining initial access to target environments, the attacks were found to drop multiple executable files via PowerShell to conduct network scanning, information theft, and XMRig cryptocurrency mining by abusing the victim's computing resources.

Over 4,000 ISP IPs Targeted in Brute-Force Attacks

Before executing the payload, there is a preparatory phase that includes disabling security product features and terminating services related to cryptominer.

The stealing malware, in addition to being able to take screenshots, serves a similar purpose to a clipping malware designed to steal clipboard content by searching for wallet addresses for cryptocurrencies such as Bitcoin (BTC), Ethereum (ETH), Binance Chain BEP2 (ETHBEP2), TRTCX (TRTCONL), and Litecoin (TROCONL).

The collected information is then transferred to a Telegram bot. A binary file is also dropped on the infected machine, which in turn, launches additional payloads.

See also: Cisco: Brute-force attacks target VPN services

Security against Brute-Force attacks on ISPs

  • Prevent with complexity: Using long and complex passwords (a combination of uppercase and lowercase letters, numbers, and special characters) makes a Brute-Force attack more difficult.
  • Countermeasures: Systems with login attempt limits or using CAPTCHA or other security mechanisms can reduce the effectiveness of these attacks.
  • Using other encryption methods: Using encryption algorithms such as bcrypt, scrypt, and Argon2 offers greater security, as they include "slow" encryption processes that make Brute-Force attacks more time-consuming.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS