Bashlite Updated with Mining and Backdoor Commands
ID: 2170ba36-5322-5a08-a428-4e50630b6980
STIX ID: report--2170ba36-5322-5a08-a428-4e50630b6980
Feed Name: TrendAI Security Blog
Executive summary: The report analyzes a variant of the Bashlite IoT botnet that abuses a Metasploit RCE against WeMo UPnP-enabled devices to deploy a dropper which fetches architecture-specific payloads; the malware provides multiple DDoS flood commands, backdoor functions, cryptocurrency-mining and bricking capabilities, and includes C2 IPs, SHA-256 hashes, and malicious URLs observed in the wild across several countries, with vendor disclosure and mitigation guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
