Saturday , November 23 2024
world map

Joint cybersecurity advisory
Botnet infects 260,000 SOHO routers, IP cameras with malware

The FBI has alerted that cyber actors have compromised over 260,000 internet-connected devices, mainly routers, to form a large botnet for malicious activities, including distributed denial of service attacks and identity concealment.

CERT-In Flags Multiple Critical Vulnerabilities in Zoom app

CERT-In issued a security advisory for multiple vulnerabilities in the Zoom app that could let attackers access sensitive information, escalate...
Read More
CERT-In Flags Multiple Critical Vulnerabilities in Zoom app

Daily Security Digest Dated 11/23/24

Every day a lot of cyberattack happenings around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Digest Dated 11/23/24

SafetyDetectives’ Research
Malware evades Microsoft Defender and 2FA, stealing $24K in crypto (video)

SafetyDetectives researchers found that Microsoft Defender was tricked by malware which allowed cryptocurrency theft from a user while analyzing a...
Read More
SafetyDetectives’ Research  Malware evades Microsoft Defender and 2FA, stealing $24K in crypto (video)

Over 145,000 ICS Across 175 Countries Found Exposed Online

A study by Censys found that more than 145,000 Industrial Control Systems (ICS) are exposed online in 175 countries, highlighting...
Read More
Over 145,000 ICS Across 175 Countries Found Exposed Online

World to see AI powered “human washing machines”

Osaka-based showerhead maker Science Co. is developing a new version of human washing machine based on cutting-edge technology. The company...
Read More
World to see AI powered “human washing machines”

Hacker compromised over 2000 Palo Alto Networks Firewalls

Over 2,000 Palo Alto Networks firewalls have been compromised in a widespread attack using two recently patched vulnerabilities (CVE-2024-0012 and...
Read More
Hacker compromised over 2000 Palo Alto Networks Firewalls

“Forces Penpals” exposed US and UK Military Social Network’s 1 Million Records

Renowned cybersecurity researcher Jeremiah Fowler uncovered a non-password-protected database having over 1.1 million records linked to Conduitor Limited (Forces Penpals)....
Read More
“Forces Penpals” exposed US and UK Military Social Network’s 1 Million Records

CVE-2024-51503
Trend Micro released updates for Deep Security Agent RCE

Trend Micro released a security update for Deep Security 20 Agent Manual Scan Command Injection RCE Vulnerability (CVE-2024-51503) that resolves...
Read More
CVE-2024-51503  Trend Micro released updates for Deep Security Agent RCE

Apple Releases Patch for two Actively Exploited Zero-Day

Apple released critical updates for its various products including for iOS, iPadOS, macOS, visionOS, and Safari to fix two zero-day...
Read More
Apple Releases Patch for two Actively Exploited Zero-Day

Maxar Space Data Leak, Company admit, Investigation ongoing!

Maxar Space Systems has verified a major data breach that exposed particular information of current and former workers. The breach...
Read More
Maxar Space Data Leak, Company admit, Investigation ongoing!

The FBI advisory states that a botnet, managed by the China-based Integrity Technology Group, has been active since mid-2021.

The botnet is primarily active in the US, with 126,000 compromised devices as of June 2024, followed by Vietnam with 21,100 and Germany with 18,900.

The main targets of the threat actor are small office/home office (SOHO) routers, firewalls, network-attached storage (NAS), and Internet of Things (IoT) devices like webcams and IP cameras. While many of these devices are outdated, a significant portion of the botnet includes those still supported by their vendors.

“This botnet infrastructure is comprised of a network of devices, known as “bots,” which are infected with a type of malware that provides threat actors with unauthorized remote access,” the advisory reads.

The FBI reports that IP addresses from China Unicom’s Beijing network, linked to a botnet, were also involved in hacking activities against US targets. This is connected to the threat group known as Flax Typhoon, RedJuliett, and Ethereal Panda.

According to Reuters, the FBI has neutralized a threat actor by seizing thousands of compromised devices. This operation is similar to the one against Volt Typhoon earlier this year.

The threat actor uses Mirai malware to take control of devices. Its source code was made public in 2016, leading to the use of Mirai botnets for various malicious activities.

“To recruit a new “bot,” the botnet system first compromises an internet-connected device using one of a variety of known vulnerability exploits. Post-compromise, the victim device executes a Mirai-based malware payload from a remote server,” the FBI explains.

More than 80 subdomains of “w8510.com” connected to the botnet’s command and control servers, along with other domains. Researchers found databases on these servers containing over 1.2 million records of compromised devices, including 385,000 unique devices belonging to victims in the US.

The threat actor is expanding the botnet, now using at least 50 different versions of Linux.

The FBI advises device owners and network defenders to take steps to prevent IoT devices from joining a botnet.

Recommended mitigations include disabling unused services and ports, implementing network segmentation, monitoring high network traffic, promptly applying patches and updates, using strong passwords instead of defaults, periodically rebooting devices, and replacing outdated equipment.

Check Also

diagram

“Sarcoma” ransomware group
Hacker to disclose “Popular Life Insurance” 36 GB of stolen data

“Sarcoma” ransomware group attacked a well known Bangladeshi insurance company named “Popular life insurance company …

Leave a Reply

Your email address will not be published. Required fields are marked *