Unveiling NKAbuse: a new multiplatform threat abusing the NKN protocol
ID: 2619c822-9b36-57f3-827b-b9a45897ebf9
STIX ID: report--2619c822-9b36-57f3-827b-b9a45897ebf9
Feed Name: Securelist by Kaspersky
NKAbuse is a Go-written, multiplatform Linux implant and botnet backdoor that leverages the NKN peer-to-peer/blockchain network for resilient and anonymous command-and-control. Delivered via exploitation of an Apache Struts2 vulnerability (CVE-2017-5638) against at least one financial organization, the implant supports eight CPU architectures (including amd64, ARM, and MIPS), persists via cron when running as root, offers an extensive set of DDoS flooding payloads plus RAT capabilities (screenshots, command execution, file operations), and Kaspersky telemetry shows victims in Colombia, Mexico, and Vietnam; host IOCs include files under /root/.config/StoreService.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
