• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

Realtek and Cacti flaws now actively exploited by malware botnets

Bill Toulas by Bill Toulas
March 30, 2023
Reading Time: 2 mins read
0
PlugX malware hides on USB devices to infect new Windows hosts

Botnet

RELATED POSTS

New Horabot campaign takes over victim’s Gmail, Outlook accounts

Windows 11 will let you view phone photos in File Explorer

Harvard Pilgrim Health Care ransomware attack hits 2.5 million people

Multiple malware botnets actively target Cacti and Realtek vulnerabilities in campaigns detected between January and March 2023, spreading ShellBot and Moobot malware.

The targeted flaws are CVE-2021-35394, a critical remote code execution vulnerability in Realtek Jungle SDK, and CVE-2022-46169, a critical command injection flaw in the Cacti fault management monitoring tool.

Both flaws have been exploited by other botnet malware in the past, including Fodcha, RedGoBot, Mirai, Gafgyt, and Mozi.

Fortinet reports that the volume of the malicious activity in 2023 is significant, targeting exposed network devices to enlist them in DDoS (distributed denial of service) swarms.

While Fortinet’s report does not explicitly state if the same threat actors spread Moobot and ShellBot, payloads were observed exploiting the same flaws in overlapping attack bursts.

Moobot infections

Moobot, a variant of Mirai, was first discovered in December 2021, targeting Hikvision cameras. In September 2022, it was updated to target multiple D-Link RCE flaws.

Buy JNews
ADVERTISEMENT

Currently, it targets CVE-2021-35394 and CVE-2022-46169 to infect vulnerable hosts, then downloads a script containing its configuration and establishes a connection with the C2 server.

Moobot continues to exchange heartbeat messages until it recognizes an incoming command, which is when it initiates its attack.

A notable feature of new Moobot versions is their ability to scan for and kill processes of other known bots so that they can harvest the maximum hardware power of the infected host to launch DDoS attacks.

ShellBot attacks

ShellBot was first spotted in January 2023 and continues to be active today, primarily targeting the Cacti flaw. Fortinet captured three malware variants, indicating that it is being actively developed.

The first variant establishes communication with the C2 and awaits the reception of one of the following commands:

  • ps – perform a port scan on the specified target and port
  • nmap – perform a Nmap port scan on a specified port range
  • rm – delete files and folders
  • version – send version information
  • down – download a file
  • udp – initiate UDP DDoS attack
  • back – inject reverse shell

The second variant of ShellBot, which first appeared in March 2023 and already counts hundreds of victims, features a much more extensive set of commands, as shown below:

Commands supported by a ShellBot variant
Commands supported by a ShellBot variant (Fortinet)

Interestingly, the malware features an exploit enhancement module that aggregates news and public advisories from PacketStorm and milw0rm.

The recommended action to defend against Mootbot and ShellBot is to use strong administrator passwords and apply the security updates that fix the mentioned vulnerabilities.

If your device is no longer supported by its vendor, it should be replaced with a newer model to receive security updates.

Share54Tweet34Pin12
Bill Toulas

Bill Toulas

Related Posts

Beware: Hackers now use OneNote attachments to spread malware
Cyber Security

New Horabot campaign takes over victim’s Gmail, Outlook accounts

June 1, 2023
Windows 11 will let you view phone photos in File Explorer
Cyber Security

Windows 11 will let you view phone photos in File Explorer

June 1, 2023
Latitude cyberattack leads to data theft at two service providers
Cyber Security

Harvard Pilgrim Health Care ransomware attack hits 2.5 million people

June 1, 2023
Apple fixes recently disclosed zero-days on older iPhones and iPads
Cyber Security

Russia says US hacked thousands of iPhones in iOS zero-click attacks

June 1, 2023
Hackers turn to Google search ads to push info-stealing malware
Cyber Security

Google triples rewards for Chrome sandbox escape chain exploits

June 1, 2023
OSV and the Vulnerability Life Cycle
Cyber Security

Announcing the Chrome Browser Full Chain Exploit Bonus

June 1, 2023

Recommended Stories

Where USDT, USDC, BUSD stand as stablecoin race accelerates

Where USDT, USDC, BUSD stand as stablecoin race accelerates

March 22, 2023
I asked ChatGPT Shiba Inu’s price prediction, the answer was simply hilarious

I queried ChatGPT Shiba Inu’s price prediction, it amused me with this answer

April 2, 2023
LockBit ransomware gang claims Royal Mail cyberattack

LockBit ransomware gang claims Royal Mail cyberattack

February 7, 2023

Popular Stories

  • New Python malware backdoors VMware ESXi servers for remote access

    Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

    137 shares
    Share 55 Tweet 34
  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • Exploit released for actively abused ProxyNotShell Exchange bug

    137 shares
    Share 55 Tweet 34
  • New Windows Server updates cause domain controller freezes, restarts

    136 shares
    Share 54 Tweet 34
  • Bing Chat’s secret modes turn it into a personal assistant or friend

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • How Ethereum’s falling gas fees affect the network
  • Here’s what Solana can expect next
  • XRP traders, know this about the ‘golden pocket’

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?