A malware that was designed to carry out brute-force attacks against websites using popular content management systems such as WordPress and Joomla has begun to be used to attack email and FTP servers.
The malware, known as Fort Disco, was discovered in August by researchers at Arbor Networks. The company estimates that it had infected more than 25,000 Windows computers and was used to guess administrator passwords for more than 6,000 WordPress, Joomla, and DataLife websites.
Once it infects a computer, the malware connects to the command and control (C&C) server to get instructions, which typically include a target list of thousands of websites and password dictionaries that will aid the malware's attempt to gain access to administrator accounts.
The malware is called Fort Disco and appears to be evolving, according to security firm Abuse.ch, a botnet detection service. This time it appears to be targeting POP3 and FTP accounts, InfoWorld reports.
Post Office Protocol, version 3 (POP3) allows email clients to connect to email servers and retrieve messages from existing accounts.
The C&C server in this Disco Fort variant responds with a list of domains accompanied by corresponding MX records (mail exchange records). MX records specify which servers handle email service for the specific domains.
The C&C server also provides a list of standard email accounts – usually with information for admin, info and support emails – for the malware to brute-force to try to discover the password, Abuse.ch reports.
Source: secnews.gr
