A Gigantic IoT Botnet Has Grown in the Shadows in the Past Month

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Since mid-September, a new IoT botnet has grown to massive proportions. Codenamed IoT_reaper (Reaper for this article), researchers estimate its current size at nearly two million infected devices.

According to researchers, the botnet is mainly made up of IP-based security cameras, network video recorders (NVRs), and digital video recorders (DVRs).

Based on Mirai, but not a Mirai offspring
Researchers from Chinese security firm Qihoo 360 Netlab and Israeli security firm Check Point have spotted and analyzed the botnet as it continued to grow during the past month.

Both companies say the botnet uses some code from the Mirai IoT malware, but there are also many new things that make the botnet a standalone threat in its own right.

The biggest difference between Reaper and Mirai is its propagation method. Mirai scanned for open Telnet ports and attempted to log in using a preset list of default or weak credentials.

Reaper does not rely on a Telnet scanner, but primarily uses exploits to forcibly take over unpatched devices and add them to its command and control (C&C) infrastructure.

Netlab says that Reaper, at the time of writing, primarily uses a package for nine vulnerabilities: D-Link 1, D-Link 2, Netgear 1, Netgear 2, Linksys, GoAhead, JAWS, Vacron, and AVTECH. Check Point also spotted the botnet attacking MicroTik adn TP-Link routers, Synology NAS devices, and Linux servers.

Reaper "baby" botnet is still growing
Netlab experts say the botnet it's in incipient stages of development, with its operator busy adding as many devices to the fold as possible.

Exploits are added on a regular basis, while the C&C infrastructure expands to accommodate new bots.

Netlab says that it observed over two million infected devices sitting in the botnet's C&C servers' queue, waiting to be processed. Just yesterday, only one of the C&C servers was controlling over 10,000 bots.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top