News: 1591378509

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Kind of goes without saying, but fix your admin passwords or risk getting borged by this brute-forcing botnet

(2020/06/05)


Servers are being targeted with a malware attack that uses its infected hosts to brute-force other machines.

Known to Akamai researchers as [1]Stealthworker , the infection preys on weak passwords then uses a massive arsenal of malware to overtake Windows and Linux servers running popular CMS, publishing, and hosting tools.

Akamai senior security researcher Larry Cashdollar (yes, that is his last name, and yes, he is tired of that joke) discovered the attack while operating an intentionally exposed Wordpress/MySQL container that for some reason was dealing in massive amounts of traffic.

"I log into the system and I see a ton of connections between my system and dozens of WP sites around the internet," Cashdollar told The Register .

"I notice the traffic is WordPress login attempts, my system is attempting to log into their WordPress login page with a bunch of credentials."

While combing through the log files of the obviously compromised virtual box, he stumbled upon a suspicious WordPress theme that contained a PHP file modified to install the malware.

Eventually, Cashdollar told El Reg , he was able to capture the malware in action and observe its entire life cycle, from introduction to complete server takeover.

Here's how it works. Stealthworker begins its attack with a distributed brute-force attack. Infected machines each hit the target with a number of login attempts using common passwords. By breaking up the attempts among multiple machines, the attacker can avoid limits on the number of login attempts.

Oh cool, tech service prices are plummeting. And by tech services, we mean botnet rentals and stolen credit cards [2]READ MORE

Once the admin password is guessed (in this case for WordPress, though Stealthworker also targets Drupal, Joomla, Magento, MySQL, and a host of others), the malware then runs through the steps of installing and deleting various components. For WordPress, a modified version of the Alternate-Lite theme leads to downloaders that target the back end and look to overtake the entire server via applications such as cPanel and WMH.

The end result is a fully pwned Windows or Linux server at the command of the botnet owner. Akamai researchers say that when their infected test systems were wiped clean of the malware itself, the botnet would reinfect those machines within minutes. It was only when passwords were changed that the infection could be eradicated once and for all.

Eventually the server is instructed to dial its command-and-control host, where it is given its instructions to join with other servers in attempting to brute-force the passwords of other machines. In the process we are told, all passwords collected from the pwned machine get added into the list of logins that the botnet attempts on other machines.

Other than attempting to assimilate other servers, the intent of the Stealthworker malware is not really clear. There's also not much in the way of how many people are using the attack, it could be one large operation, or several groups with the same tools.

Akamai researcher Steve Ragan notes that while there is some indication that scraping tools such as MageCart could be used on the servers, the full control the malware affords to the attacker opens the door to just about any sort of malicious venture.

"What they get is this broad network of vulnerable servers and websites they can use for anything," Ragan explained.

"The endgame is pretty much whatever the attacker feels like doing."

While the Stealthworker attack is a nasty one and difficult to fully remove, the solution is rather simple. Akamai recommends that admins make sure all of their passwords are complex and difficult to guess. As the attack preys on weak credentials, that one simple step should keep everything safe. ®



[1] https://blogs.akamai.com/sitr/2020/06/stealthworker-golang-based-brute-force-malware-still-an-active-threat.html

[2] https://www.theregister.com/2020/05/27/criminal_services_cheaper/

Nasty

Pen-y-gors

But mitigation isn't too difficult.

I have some WP sites (thankfully few) but security plugins (All-In-One???) really reduce the risk. Not using default login page names, locking out the site after multiple failed logins etc.

But I've noticed for years that my server logs are full of failed attempts at logging in to WP, even when I don't use WP!

Surely there is some way to develop IP blacklists for addresses that clock up, say, 50 failed WP login attempts in 24 hours, and the ISP then kills the IP address and tells all the others.

Re: Nasty

IGotOut

I've noticed big uptick in login attempts (DigitalOcean looking at your clients).

Mitigated 99% of these by Cloudflare by blocking any variation of Wp-admin or wp-login from outside the uk. Known bad ISPs from UK get challenge response before they can proceed.

Then it has to get past wordfence and 2FA.

A green hunting cap squeezed the top of the fleshy balloon of a head. The
green earflaps, full of large ears and uncut hair and the fine bristles that
grew in the ears themselves, stuck out on either side like turn signals
indicating two directions at once. Full, pursed lips protruded beneath the
bushy black moustache and, at their corners, sank into little folds filled
with disapproval and potato chip crumbs. In the shadow under the green visor
of the cap Ignatius J. Reilly's supercilious blue and yellow eyes looked down
upon the other people waiting under the clock at the D. H. Holmes department
store, studying the crowd of people for signs of bad taste in dress. Several
of the outfits, Ignatius noticed, were new enough and expensive enough to be
properly considered offenses against taste and decency. Possession of
anything new or expensive only reflected a person's lack of theology and
geometry; it could even cast doubts upon one's soul.
-- John Kennedy Toole, "Confederacy of Dunces"