HomeSecurityPumaBot botnet forces SSH credentials to compromise devices

PumaBot botnet forces SSH credentials to compromise devices

A new Go-based botnet malware for Linux, dubbed PumaBot, was recently detected and is used to brute-force SSH credentials on embedded IoT devices, with the aim of installing malicious payloads.

See also: DanaBot Botnet operation disrupted, 16 suspects found

PumaBot botnet

The targeted nature of PumaBot is evident, as instead of scanning the internet broadly, it attacks specific IP addresses that it receives from a command and control (C2) server, rather than through a general scan. Darktrace documented PumaBot ’s activity in a report, which presents the botnet’s attack flow, indicators of compromise (IoCs), and detection rules. The malware receives a list of targeted IPs from its C2 server (ssh.ddos-cc.org) and attempts to brute-force port 22, which is used for SSH access.

During this process, PumaBot checks for the presence of the string “Pumatronix”, which Darktrace believes may be related to targeted attacks on surveillance systems and traffic cameras provided by this manufacturer.

Once the targets are determined, the malware receives credentials and tests them. If the connection is successful, it runs the uname -a to gather information about the environment and confirm that the device is not a honeypot (malware analysis trap).

It then writes its main executable (named jierui ) to the /lib/redis directory and installs a systemd service named redis.service , ensuring that it persists even after a device reboot . Finally, it inserts its own public SSH key into the authorized_keys file , so that it maintains access even if the original payload is removed during a system cleanup

When the infection remains active, the PumaBot botnet can receive commands to extract data, insert new payloads, or steal information that can be used for lateral movement within the network.

See also: USA: Charges against the creator of the Qakbot botnet

Examples of malicious payloads that Darktrace include:

  • self-updating scripts,
  • PAM rootkits that replace the legitimate pam_unix.so,
  • and malicious services (such as the binary file named “1”).
PumaBot botnet forces SSH credentials to compromise devices

The malicious PAM module collects local and remote SSH login credentials and stores them in a text file named con.txt. The binary “watcher” (1) constantly monitors for the existence of this file and then sends it to the C2 server. After extracting the data, the text file is deleted from the infected computerto eliminate any traces of the malicious activity.

The size and success of the PumaBot botnet remain unknown at this time, and Darktrace does not disclose the extent of the lists of targeted IP addresses.

This particular botnet stands out because it performs targeted attacks, which could be a gateway for deeper penetration into corporate networks, unlike other malware that uses infected IoT devices for simpler forms of cybercrime, such as denial-of-service (DoS) attacks or as proxies for network coverage.

To protect against botnet threats, it is recommended to:

  • to upgrade IoT devices to the latest available software version,
  • change the default access credentials,
  • be placed behind firewalls,
  • and be isolated on separate networks, away from critical or sensitive systems.

See also: New HTTPBot Botnet Targets Windows Machines

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Based on the above, it becomes clear that the PumaBot botnet is not just another botnet that exploits vulnerable IoT devices for typical malicious activities, but is a more sophisticated and targeted intrusion tool. The fact that it does not perform mass scans, but targets specific IPs from lists it receives from a C2 server, indicates that the attacks are carefully planned and probably directed at specific organizations or infrastructures.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS