NKabuse backdoor harnesses blockchain brawn to hit several architectures
ID: 80a36cf8-197e-5f3c-8bfd-ff799a19d83f
STIX ID: report--80a36cf8-197e-5f3c-8bfd-ff799a19d83f
Feed Name: The Register (Security)
A Go-based multi-platform backdoor called "NKAbuse" was found using the New Kind of Network (NKN) P2P/blockchain protocol for anonymized C2. NKAbuse exploits a public PoC for Apache Struts 2 (CVE-2017-5638) to install architecture-specific payloads (eight architectures, prioritizing Linux), achieves persistence via cron, supports RAT functions (remote command execution, file listing, screenshots) and 12 DDoS attack types, and has been observed in victims in Mexico, Colombia, and Vietnam.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
