Chaos malware expands from routers to Linux cloud servers
ID: de556368-75ec-5201-b094-1b5478d14204
STIX ID: report--de556368-75ec-5201-b094-1b5478d14204
Feed Name: Help Net Security
Darktrace’s CloudyPots honeypot captured a new x86-64 Linux build of the Go-based Chaos botnet that exploited a misconfigured Apache Hadoop resource manager to retrieve and execute a binary. The sample includes persistence via systemd, DDoS modules (HTTP, TLS, TCP, UDP, WebSocket) and a newly added SOCKS5 proxy capability allowing attackers to route traffic through compromised cloud servers; delivery and infrastructure connect to domains previously tied to Chinese-language campaigns and ValleyRAT distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
