Pienk botnet besmet oor 1.5 miljoen toestelle

Die Netlab Qihoo 360 research team reports that it has discovered the “grootste botnet” in the past six yearsPink malware has already infected more than 1.6 miljoen toestelle, mostly located in China (96%).

These bots are used by botnet operators for DDoS attacks and injecting ads on HTTP sites. It is reported that at least 100 DDoS attacks have been carried out by the botnet to date.

Pienk botnet

According to experts, Pienk has been active since November 2019. The malware mainly attacks MIPS routers and uses various third-party services, including GitHub, as well as P2P and centralized C&C servers to connect bots with operators and transfer commands.

Pink is a hybrid architecture botnet that uses bothP2Pand central “C2to communicate to its bots. Algehele, it delivers less time-sensitive commands (e.g. management configuration information) via P2P, while more time-sensitive commands are distributed centrally via the C2s (e.g. launching ddos attacks, inserting advertisements into HTTP websites visited by users).Netlab Qihoo 360 experts told.

Pink also uses DNS-Over-HTTPS to connect to the server specified in the configuration file, which is either delivered via GitHub or Baidu Tieba (sometimes the domain name is completely hardcoded).

Pink’s operators fought with the supplier to control the infected devices: while the supplier made repeated attempts to fix the problem, the master bot detected the supplier’s actions in real time and repeatedly updated the firmware of the routers accordingly.the analysts say.
According to another Chinese company, NSFOCUS, the malware spreads through the exploitation of 0-dag vulnerabilities in network devices. And although today a significant proportion of such devices have been fixed and restored to their previous state, the botnet is still active and consists of no less than 100,000 toestelle.

Let me remind you that we also talked about the fact that the Chinese authorities have arrested the authors of the Mozi botnet.

Helga Smith

Ek het altyd in rekenaarwetenskap belanggestel, veral datasekuriteit en die tema, wat deesdae genoem word "data wetenskap", sedert my vroeë tienerjare. Voordat u as hoofredakteur in die virusverwyderingspan kom, Ek het as 'n kuberveiligheidskenner in verskeie maatskappye gewerk, including one of Amazon's contractors. Nog 'n ervaring: Ek het onderrig in Arden en Reading universiteite.

Los 'n antwoord

Your email address will not be published. Required fields are marked *

Hierdie webwerf gebruik Akismet om strooipos te verminder. Leer hoe jou opmerkingdata verwerk word.

Terug na bo-knoppie