HomeSecurityNew XorDDoS malware allows creation of DDoS botnet

New XorDDoS malware allows creation of DDoS botnets

A significant development in the field of DDoS has been identified, as the latest version of the XorDDoS malware continues to spread globally as of November 2023.

See also: New Mirai botnet behind rise in TVT DVR exploit

New XorDDoS malware allows creation of DDoS botnets

This trojan, which targets Linux systems, turns infected machines into “zombie bots” that can be coordinated to perform powerful DDoS attacks against specific targets. The malware spreads primarily through brute-force attacks on the SSH protocol, trying a multitude of root credential combinations on thousands of servers until it gains access to vulnerable Linux devices. Once inside a system, the XorDDoS malware installs sophisticated persistence mechanisms, ensuring its automatic launch at system startup and effectively avoiding detection by security products.

Cisco Talos researchers found that over 70% of attacks using XorDDoS targeted the United States during the monitoring period.

Analysis of the language settings in the malware's multi-layered controller, creation tool, and login functions suggests that the operators are Chinese speakers.

See also: Eleven11bot botnet has infected 86,000 devices for DDoS attacks

This central controller allows cybercriminals to simultaneously manage multiple individual controllers of the XorDDoS malware, significantly enhancing their ability to coordinate large-scale attacks. The geographic impact extends beyond the United States, as infected systems attempt to target and attack several countries, including Spain, Taiwan, Canada, Japan, Brazil, and several European countries.

New XorDDoS malware allows creation of DDoS botnets

The infection process begins when XorDDoS manages to compromise a Linux device via brute-force attacks on SSH. Once it gains access, it installs a malicious shell script, which implements strong persistence mechanisms on the system via init files and cron jobs. The malware ensures its continuous operation by installing init scripts in multiple boot levels and adding a cron job that runs every three minutes.

Once the URLs or IPs are decrypted, they are added to a remote list that is used to establish communication with the command-and-control servers. This advanced encryption mechanism helps the malware evade detection while maintaining constant communication with its operators.

See also: Vo1d malware botnet targets more and more Android TVs

Based on the above, it is clear that the XorDDoS malware has a highly organized and resilient ecosystem of malicious operation, which allows it to remain active for long periods of time without being easily detected. The use of remote lists to communicate with command and control servers, combined with encryption and persistent presence mechanisms, makes it one of the most sophisticated botnets targeting Linux systems.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS