News: 1653289033

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft sounds the alarm on – wait for it – a Linux botnet

(2022/05/23)


Microsoft has sounded the alarm on DDoS malware called XorDdos that targets Linux endpoints and servers.

The trojan, first discovered in 2014 by security research group MalwareMustDie, was named after its use of XOR-based encryption and the fact that is amasses botnets to carry out distributed denial-of-service attacks. Over the last six months, Microsoft threat researchers say they've witnessed a 254 percent spike in the malware's activity.

"XorDdos depicts the trend of malware increasingly targeting Linux-based operating systems, which are commonly deployed on cloud infrastructures and Internet of Things (IoT) devices," Redmond [1]warned .

[2]

And to illustrate this trend, Redmond noted that over the course of the XorDdos malware's 8-year reign of terror, it has hit a whopping (checks Microsoft's numbers)... err, we have no idea how many devices it has infected. The blog doesn't say. It also doesn't give any baseline for the 254 percent increase. And Microsoft said it wouldn't have them until the middle of next week.

[3]

[4]

To be clear: we are not minimizing the disruptive nature of DDoS attacks, which, as we've seen in recent months, can be [5]weaponized by rogue nations and other miscreants to knock government agencies and businesses offline. And when these botnets disrupt websites providing news and public services information in combat zones, DDoS activity becomes even more dangerous.

"DDoS attacks in and of themselves can be highly problematic for numerous reasons, but such attacks can also be used as cover to hide further malicious activities, like deploying malware and infiltrating target systems," the Microsoft 365 Defender Research Team wrote.

[6]

We wholeheartedly agree.

[7]Microsoft points at Linux and shouts: Look, look! Privilege-escalation flaws here, too!

[8]Monero-mining botnet targets Windows, Linux web servers

[9]Cloudflare stomps huge DDoS attack on crypto platform

[10]DDoS attacks at an all-time-high in Q1 2022, says Kaspersky

But you know what else is equally dangerous as Linux botnets? Windows botnets.

Take the Windows-device-targeting Purple Fox malware, for example, which was also discovered in 2018.

Guardicore security researchers recently [11]wrote about how this botnet's malicious activity has jumped 600 percent since May 2020, and infected more than 90,000 devices in the past year alone. But Microsoft didn't blog about this one.

To be fair, Microsoft's Security Intelligence team this week did [12]warn about a new variant of the Sysrv moreno-mining botnet that targets both Linux and Windows systems.

[13]

But from where we sit, it definitely appears that Redmond finds a whole lot more joy in [14]bashing Linux than, say, looking in the mirror at its own flaws.

How XorDdos evades detection

In the new blog about XorDdos, Microsoft noted that the malware uses secure shell (SSH) brute force attacks to gain control on target devices. Once it successfully finds the right root credential combination, it uses one of two methods for initial access, both of which result in running a malicious ELF file – the XorDdos malware.

The binary is programmed in C/C++ and its code is modular, according to the research team. And it uses specific functionalities to evade detection.

As noted above, one of these is XOR-based encryption to obfuscate data. Additionally, XorDdos uses daemon processes – these are processes running in the background – to break process tree-based analysis. The malware also uses its kernel rootkit component to hide its processes and ports, thus helping it evade rule-based detection.

Additionally, the stealthy malware uses several persistence mechanisms to support different Linux distributions, so it's good at infecting a range of different systems.

"XorDdos and other threats targeting Linux devices emphasize how crucial it is to have security solutions with comprehensive capabilities and complete visibility spanning numerous distributions of Linux operating systems," Redmond noted in the blog.

And guess who just happens to sell said security solutions? ®

Get our [15]Tech Resources



[1] https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YotbRdHTGBFc@buKP-jpEAAAAMo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YotbRdHTGBFc@buKP-jpEAAAAMo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YotbRdHTGBFc@buKP-jpEAAAAMo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/04/26/kaspersky_ddos_up/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YotbRdHTGBFc@buKP-jpEAAAAMo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/04/27/microsoft-linux-vulnerability/

[8] https://www.theregister.com/2022/05/18/microsoft-cryptomining-sysrv-k/

[9] https://www.theregister.com/2022/04/28/cloudflare-largest-ddos-attack-/

[10] https://www.theregister.com/2022/04/26/kaspersky_ddos_up/

[11] https://www.guardicore.com/labs/purple-fox-rootkit-now-propagates-as-a-worm/

[12] https://www.theregister.com/2022/05/18/microsoft-cryptomining-sysrv-k/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YotbRdHTGBFc@buKP-jpEAAAAMo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2022/04/27/microsoft-linux-vulnerability/

[15] https://whitepapers.theregister.com/



knock, knock.

Pete 2

> the malware uses secure shell (SSH) brute force attacks to gain control on target devices.

So basically this is a 254% increase in easily guessed root passwords on systems exposed to the internet.

Re: knock, knock.

Androgynous Cupboard

I'd assumed that, given SSH as root is almost always disabled by default, they were going in as regular users and then trying for sudo. But apparently not: From the report

> It uses a malicious shell script to try various root credential combinations across thousands of servers

Well, that's not going to be terribly effective is it? Banging on a locked door.

Re: knock, knock.

Dave Null

Depends. Are all those millions of doors locked? Or are they made up of a bunch of insecure Internet of Shit devices that are out there in the consumer space, that maybe have default PWs?

Re: knock, knock.

Peter Gathercole

Most of the IoT devices running old versions of Linux will be attached to LANs behind a NAT router. This makes it impossible for someone on the Internet to even get to them to try to brute force the root password.

The only exception to this is if the IoT device uses UPnP to knock holes in the firewall and NAT protection that the router provides. But they would be NUTS to open port 22 via UPnP, even if it were possible.

I suppose that it may be possible that they run SSH on a non-standard port, and ask that to be opened via uPnP, but I would be surprised if they even did that, and if they did, it would be a case of guess-the-port before you even start the attack.

Anyway, all sensible people turn UPnP of on their router, don't they?

I monitor inbound intrusion attempts on my home network (I have a full-port redirect to a Linux firewall - which had password login disabled in the SSH config, in case you ask), I noticed an uptick of login attempts (at it's peak it was about 100 a minute, from about half-a-dozen different source addresses) using a variety of user ID and passwords just after the new year. As a precaution, I switched off the port redirect, and I've not needed to turn it back on, so it has remained off. But there was definitely something going on. Not sure if I was being specifically targeted, but that seems a little unlikely.

Dear Microsoft.

ShadowSystems

Before you start crowing about how insecure the competition can be, take a look at your own utterly abysmal track record of fatal security flaws. I'd hazard a guess that everyone else's security screw ups don't measure up to the Olympus Mons of the MS fuck ups in the same time frame.

I mean, how many times does MS have to release a fix to fix the fix that broke the previous fix? I'm fairly sure that a functioning quality assurance team testing your code before it was allowed past the gates just might, just *might* mind you, go some way into caulking the holes of the security Swiss cheese that is your fortress walls.

Re: Dear Microsoft.

werdsmith

Before you start crowing about how insecure the competition can be, take a look at your own utterly abysmal track record of fatal security flaws

Here we go again. Whataboutery of the first order. The massive chip on the shoulders of people who have to make this about OS wars was amusing but seems increasingly emotionally immature.

Dear Microsoft, Thanks for the help MS, we will address this and be ready for the inevitable next one. Any more help you can give us, will be more than welcome. Because that's how the grown ups operates.

Isn't Azure built on Linux?

Roland6

Suspect MS are suffering from this since as they say: Microsoft threat researchers say ..."XorDdos depicts the trend of malware increasingly targeting Linux-based operating systems, which are commonly deployed on cloud infrastructures and Internet of Things (IoT) devices,"

Using Linux is a great way to deflect criticism: the problems MS are experiencing in the Azure cloud infrastructure is not to do with MS (proprietary) software but with Linux...

XorD

steelpillow

I'll bet you a dollar a dime that XorDos has moved across to SystemD and dropped support for Init and friends.

Now I can smirk even more broadly every time I boot Devuan.

Not the most balanced

monkeylite

Not saying Microsoft are blameless (by a massive margin) but I got the impression that the journalist wasn't even trying to write from a neutral position here..

Re: Not the most balanced

veti

If you're looking for "neutral" writing, you're on the wrong site.

Actually, come to think of it, you're probably on the wrong Internet entirely.

It's not? Are you saying that you SHOULD allow people (other than William
Wallace) to shoot lightning bolts from their arse?
-- Seth Galbraith