HomeSecurityChaos botnet: New variant targets cloud misconfigurations

Chaos botnet: New variant targets cloud misconfigurations

Cybersecurity researchers have identified a new variant of the Chaos, which affects incorrect cloud configurations and expands the botnet.

Chaos botnet

“ The Chaos malware is increasingly targeting cloud misconfigurations, expanding beyond its traditional focus on routers and edge devices , ” Darktrace said in a new report.

Chaos botnet

Chaos was first documented by Lumen Black Lotus Labs in September 2022. It was presented as cross-platform malware , capable of targeting Windows and Linux environments to execute remote shell commands, install additional modules, spread to other hosts via brute-forcing SSH keys, mine cryptocurrencies, and launch denial-of-service (DDoS) attacks over HTTP, TLS, TCP, UDP, and WebSocket.

See also: Mac: New ClickFix attack abuses Script Editor

The malware is believed to be an evolution of another DDoS malware, known as Kaiji, that has targeted misconfigured Docker instances. It is currently unknown who is behind the malicious operation, but the presence of Chinese characters and the use of China-based infrastructure suggest that the threat actor may be of Chinese origin.

Chaos botnet: New variant targets cloud misconfigurations

New dangerous variant

Darktrace said it discovered the new variant after targeting its honeypot network last month. It was a deliberate misconfiguration of Hadoop that allowed remote code execution on the service. In the attack detected by the cybersecurity firm, the attack began with an HTTP request to the Hadoop deployment to create a new application.

The application incorporated a shell script to retrieve a Chaos agent binary from a server controlled by the attacker. The script also allowed for setting permissions to allow all users to read, modify, or execute it, then executing the binary and deleting it from disk to minimize traces.

An interesting aspect of the attack is that the domain had previously been used in a phishing email campaign carried out by the Chinese cybercrime group Silver Fox to deliver deceptive documents and the ValleyRAT malware .

See also: Zero-day attack targets Adobe Reader users

The 64-bit ELF binary is a refactored and updated version of Chaos, which restructures several of its functions while retaining most of its core features. One of the most significant changes concerns the removal of functions that allowed it to spread via SSH and exploit router vulnerabilities.

In their place is a new SOCKS proxy feature that allows the compromised system to be used for ferrying traffic, thus hiding the real sources of malicious activity and making it more difficult for defenders to detect and block the attack.

Chaos botnet: New variant targets cloud misconfigurations

“In addition, several functions previously thought to be inherited from Kaiji have now changed, suggesting that threat actors have either rewritten the malware or extensively restructured it,” Darktrace added.

The addition of the proxy feature is likely an indication that threat actors are looking to further exploit the botnet beyond cryptocurrency mining and paid DDoS attacks.

See also: APT28 exploits SOHO routers in DNS Hijacking campaign

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“While Chaos is not a new malware, its continued evolution highlights cybercriminals’ dedication to expanding their botnets and enhancing the capabilities at their disposal,” Darktrace concluded. “The recent shift in botnets like AISURU and Chaos to include proxy services as core features shows that denial-of-service is no longer the only risk pose these botnets.”

Protection

To protect against threats like Chaos, it is critical to properly secure cloud configurations (especially services like Docker and Hadoop), implement strong passwords and multi-factor authentication (MFA), and restrict access via firewall and network rules to only necessary IPs. At the same time, regular software updates, disabling unnecessary services, using threat detection tools, and constantly monitoring logs can identify suspicious activity early, significantly reducing the risk of a breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS