Symantec experts have discovered a new variant of the Chikdos DDoS-Trojan that targets MySQL servers around the world.
There is a malware that abuses MySQL Servers for DDoS attacks. Experts have named it Chikdos. The threat was first detected by CERT Poland and according to experts it has been around since 2013. Chikdos is a DDoS Trojan that is able to infect both Linux and Windows machines to use them in DDoS attacks.
"It appears that the bot was created with the sole purpose of performing DDoS. This means that the attackers are only interested in infecting machines that have a significant network bandwidth, e.g. servers. This is probably why there are two versions of the bot – Linux operating systems are a popular choice for servers," says the report published by CERT Poland.
Now, Symantec researchers have identified a new version of the Chikdos malware that shares many similarities with older versions except for its ability to target specific MySQL servers. The choice of MySQL servers as targets for attacks is not surprising, as this type of machine is very popular and usually has a lot of bandwidth that can be exploited to launch DDoS attacks.
Most attacks observed by Symantec that have compromised servers are in India, China, Brazil and the Netherlands.
Experts explained that attacks against MySQL servers begin with the injection of a malicious user-defined function (UDF) that downloads the remaining "pieces" of the Chikdos Trojan from embedded URLs. In some cases, the downloader adds a new user account to the machine.
Symantec says: "Our analysis found that the compromised servers were used to launch DDoS attacks against a Chinese IP address and a US hosting provider."
UDFs are subroutines consisting of multiple Transact-SQL statements that can be used to encapsulate code for reuse and that typically allow the functionality of a MySQL server to be extended.
Although UDFs are typically injected in SQL-injection attacks, in the case analyzed by Symantec, experts do not have a clear picture of the infection process. Possible scenarios include the use of automated scans or malware that compromised servers and installed the UDFs.
As a mitigation strategy, experts recommend avoiding, as much as possible, running SQL servers with administrative privileges, and let me remind you to patch applications that rely on SQL.

