Cyber Affairs
No Result
View All Result
  • Login
  • Register
[gtranslate]
  • Home
  • Live Threat Map
  • Books
  • Careers
  • Latest
  • Podcast
  • Popular
  • Press Release
  • Reports
  • Tech Indexes
  • White Papers
  • Contact
Social icon element need JNews Essential plugin to be activated.
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
COMMUNITY
NEWSLETTER
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
NEWSLETTER
No Result
View All Result
Cyber Affairs
No Result
View All Result
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

Zerobot botnet upgrade targets unpatched Apache servers

admin by admin
Dec 23, 2022
in Cyber Intelligence
A A
0

Zerobot, an “internet of things” botnet discovered earlier this year, has been updated with additional features, including the ability to target vulnerabilities on unpatched Apache servers.

As detailed Wednesday by researchers at Microsoft Corp.’s Security Threat Intelligence team, Zerobot is a Go-based botnet that primarily spreads through IoT and web application vulnerabilities. Zerobot is offered as part of a malware-as-a-service scheme. One domain with links to the bot was seized by the U.S. Federal Bureau of Investigation on Dec. 14.

The new version, dubbed Zerobot 1.1, has increased capabilities, including new attack methods and exploits for support architectures, expanding its reach to different types of devices, Apache servers notable among them.

Zerobot 1.1 targets vulnerabilities in Apache and Apache Spark, CVE-2021-42013 and CVE-2022-33891, respectively. Added features include the ability to target vulnerabilities in the MiniDVBLinux DVR systems, Grandstream networking systems and Roxy-WI GUI.

Upon gaining device access, Zerobot injects a malicious payload that then attempts to download several binaries to identify the architecture by brute force. Depending on the operating system, the botnet has various persistence mechanisms that are used to maintain access to infected devices. It’s noted that although Zerobot is unable to spread on Windows machines, several examples can run on Windows.

The new version of Zerobot also has additional distributed denial-of-service attack capabilities, including functions that allow the threat actors to target resources and make them inaccessible. Successful Zerobot DDOS attacks can be used to extort ransom payments, distract from other malicious activity, or disrupt operations.

“Zerobot (and other methods of forming botnet armies) is about as serious as it gets.” Bud Broomhead, chief executive officer at IoT cyber hygiene company Viakoo Inc., told SiliconANGLE. “Threat actors gain not just one foothold in your network but thousands of them when IoT and operational-technology devices are infected.”

Broomhead noted that the number of DDoS attacks is increasing in size, frequency and duration thanks to the spread of bots such as Zerobot that have mainly been unchecked.

“Threat actors will always go to where defenses are weakest and the potential for exploits is highest – and that’s exactly what IoT and OT devices offer today,” Broomhead explained. “Many cyber defenses rely on agent-based technology to protect IT systems. IoT/OT devices can’t accept agents, making IT-oriented solutions ineffective in stopping threats like Zerobot.”

Broomhead recommends that security teams should at least be using an agentless asset discovery solution so they know what assets can be compromised. Security teams should monitor devices for changes in how they function, such as increased network traffic from them, use of onboard memory, or unusual CPU usage. In addition, security teams need to stay on top of IoT/OT device firmware updates and password rotations by using an automated and agentless IoT security platform.

Image: Needpix

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Read the full article here

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

[mc4wp_form id=”387″]

Recent News

  • Understanding the Implications & Guarding Privacy- Axios Security Group
  • Hackers Actively Using Pupy RAT to Attack Linux Systems
  • Buckle Up_ BEC and VEC Attacks Target Automotive Industry

Topics

  • AI
  • Books
  • Careers
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • News
  • Podcast
  • Reports
  • Tech Indexes
  • Uncategorized
  • White Papers

Get Informed

[mc4wp_form id=”387″]

Social icon element need JNews Essential plugin to be activated.

Copyright © 2022 Cyber Affairs. All rights reserved.

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

Copyright © 2022 Cyber Affairs. All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.