Botnet Targeting SSH Servers for Crypto Mining: NoaBot

Botnet Targeting SSH Servers for Crypto Mining: NoaBot

A new botnet called NoaBot, based on Mirai, has been utilized by cyber attackers as part of a crypto mining campaign since the beginning of 2023. Mirai, whose source code was leaked in 2016, became the precursor to numerous botnets; the most recent being InfectedSlurs, capable of conducting distributed denial-of-service (DDoS) attacks. There are indications that NoaBot may be linked to another botnet campaign involving a Rust-based malicious software family called P2PInfect, which recently received an update to target routers and IoT devices.

The fact that threat actors have attempted to replace NoaBot with P2PInfect in recent attacks targeting SSH servers suggests a potential shift towards tailored malware. Despite its Mirai foundations, NoaBot’s propagation module leverages an SSH scanner to search for servers vulnerable to dictionary attacks and applies brute force to them, adding an SSH public key to the .ssh/authorized_keys file for remote access. Optionally, it can download and execute additional binary files after a successful exploit or propagate itself to new victims.

Hackdra
@hackdra Cybersecurity

Hackdra was founded in 2019 by of the sector Pioneer cyber defense experts determined to save the internet from cyber deteriorations. By combining his passion for security with the high-level artificial intelligence technology he developed, he earned the title of the industry’s “first and only Dynamic Artificial Intelligence-based cybersecurity company”. By developing innovative methods for security risks that traditional methods cannot prevent, it has gave direction the understanding of security in the sector and has made a name for itself in the world cyber security configurations.

Related Posts