216.73.217.22

Gafgyt Malware Broadens Its Scope in Recent Attacks

· Published 03/12/2024 18:15 · Modified 03/12/2024 23:03

Export JSON

Essential information

Published
03/12/2024 18:15
Modified
03/12/2024 23:03
Tags
2024-12-03 api bashlite botnet container ddos docker gafgyt iot lizkebab privilege-escalation
Related entities
25 observables, 8 techniques (mitre), 3 malware

Description

Trend Micro researchers have identified threat actors exploiting misconfigured servers to spread malware, traditionally known for targeting devices. This shift in behavior involves attackers creating containers based on legitimate 'alpine' images to deploy the malware. The attack sequence includes attempts to deploy various binaries, with the potential to launch attacks on targeted servers. The malware uses hardcoded command-and-control server addresses and can perform attacks using multiple protocols. The attackers also employ privilege escalation techniques and attempt to discover local IP addresses. This new tactic represents a significant expansion of 's targets beyond its usual scope.

External references