News: 1670333411

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

KmsdBot botnet is down after operator sends typo in command

(2022/12/06)


Somewhere out there, a botnet operator is kicking themselves and probably hoping no one noticed the typo they transmitted in a command that crashed their whole operation.

Unfortunately for the typographically-challenged botnetter, it happened on the internet, so someone knows: Akamai, in this case, had been watching for some time.

Even worse for the operator(s), their Golang-coded KmsdBot lacked persistence, meaning the whole botnet [1]is toast thanks to the apparent decision to forgo error handling.

[2]

"It's not every day you come across a botnet that the threat actors themselves crash [though] their own handiwork," said Akamai vulnerability researcher Larry Cashdollar.

[3]Google wins lawsuit against alleged Russian botnet herders

[4]Notorious Emotet botnet returns after a few months off

[5]FBI: Russian hacktivists achieve only 'limited' DDoS success

[6]Akamai: We stopped record DDoS attack in Europe

Security researchers at the content delivery network first spotted KmsdBot earlier this month, noting that it was dangerous in part because it used SSH connections with weak login credentials to infect targets. According to Akamai, the botnet was able to mine cryptocurrencies, but had also been used to launch DDoS attacks, with most of its targets associated with the gaming, tech and luxury automotive sectors.

How to crash your own botnet

Akamai set up its own modified version of KmsdBot pointed at an internal IP address to use as a controlled test environment to monitor what commands it was receiving from its C2 server.

"During the testing, we noticed the botnet stopped sending attack commands after observing a single malformed command," Cashdollar said. !bigdata www.bitcoin.com443 / 30 3 3 100

The command was likely intended to DDoS Bitcoin.com by tossing junk data at it, but check out that lack of space between the URL and port number. Oops. Most sophisticated software would know how to handle that, but not so for KmsdBot.

After reconstructing the command and tossing it at their internal KmsdBot, the Akamai researchers noticed that lack of space between URL and port number caused the Go binary to crash, throwing up an "index out of range" error because the wrong number of arguments were supplied.

[7]

The command "likely crashed all the botnet code that was running on infected machines and talking to the C2," Cashdollar said. "In our world of zero-days and burnout, seeing a threat that can be mitigated with the coding equivalent of a typo is a nice story." ®

Get our [8]Tech Resources



[1] https://www.akamai.com/blog/security-research/kmsdbot-part-two-crashing-a-botnet

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y491NrumdSG-fk-fcMN1BwAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2022/11/17/google_botnet_default_judgment/

[4] https://www.theregister.com/2022/11/17/emotet_botnet_returns/

[5] https://www.theregister.com/2022/11/08/fbi_hacktivists_useless/

[6] https://www.theregister.com/2022/08/01/ddos_europe_akamai/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y491NrumdSG-fk-fcMN1BwAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://whitepapers.theregister.com/



Disgusted Of Tunbridge Wells

Too cool for error handling

b0llchit

This is one of those rare times when the correct response is (*) :

Ha ha!

It does open a new avenue for research. Fuzzing botnets with syntax errors. There are no more deserving targets to go down, discounting the botnet creators.

(*) Thank you, Nelson

I was going to say

Victor Ludorum

Ha Ha Ha Ha Ha Ha...

But you basically beat me to it.

Ha ha!

KarMann

Me too three. Just before I opened the comments link, I went to tell my wife about this story, opening with a consciously Nelson-esque 'ha ha!' I guess it's the only righteous response to this.

Natalie Gritpants Jr

Let's hope they don't have a list of hosts they had installed the botnet on so they don't just install it again.

Who me ?

Julian 8

One for Who Me ? in a couple of years

Puhlease!

Wally Dug

Akamai vulnerability researcher Larry Cashdollar

Really? No, Shirley not?!?

fidodogbreath

Input validation FTW

Coudn't happen to 'nicer' peole

Will Godfrey

BWAAAAAA ha ha HA

Excerpts From The First Annual Nerd Bowl (#7)

JOHN SPLADDEN: In this final round, the two teams must assemble a 16-node
Beowulf cluster from scratch, install Linux on them, and then use the
system to calculate pi to 1 million digits. This is the ultimate test for
nerds... only people in the Big Leagues should attempt this... [snip]

BRYANT DUMBELL: Look at that! Instead of messing with screws, the
Portalbacks are using duct tape to attach their motherboards to the cases!
That should save some time. [snip] They've done it! The Mad Hatters have
completed the Final Round in 2 hours, 15 minutes. That's one hell of a
Beowulf cluster they produced... drool.

SPLADDEN: With that, the Mad Hatters win the Nerd Bowl 105 to 68! There's
going to be some serious beer-drinking tonight back at the Red Hat offices.

DUMBELL: Linus Torvalds has emerged from the sidelines to present his
Linus Torvalds Trophy to the winners. What a glorious sight! This has
definitely been the best Nerdbowl ever. I pity those people that have been
watching the Superbowl instead.