Skip to main content

DDoS Botnet Controlled by Tweets

A malware author has created a new DDoS botnet that is capable of being controlled by tweets that are specially coded to provide instructions to the botnet.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A malware author has created a new DDoS botnet that is capable of being controlled by tweets that are specially coded to provide instructions to the botnet.

Affected platforms

The following platforms are known to be affected:

Threat details

The specially coded tweets are designed to issue commands which can start and stop a DDoS attack.

The malware that is being used to infect compromised devices is being spread via a file named driversUpdate.exe. The Twitter account will be used to tweet out a coded message which the malware will detect and identify the command(s) to carry out. The commands that the malware will be looking for are:

wakeup – This tells the bot(s) to visit an IP address logger, which records the IP addresses of all the bots and determines the size of the botnet.

target – This command will start a DDoS attack against a specific target.

stop – This command will stop the DDoS attack.

dexe - This will download a specific file and execute it.

exe – This will execute CLI commands.

dl – This command is used to download a specific file, but will check beforehand if it already exists.

df – This command will do the same as ‘dl’, however, does not check if the file exists.

The malware’s source code shows a continued focus on creating new methods of carrying out DDoS attacks using public services such as social networks. With this method already working it does open opportunities for the malware author or others to build upon its capabilities.


Remediation steps

Type Step
  • Consider the use of a third party DDoS mitigation tool.
  • Review current DDoS mitigation tools with a view to assessing whether they are currently fit for purpose.
  • Have a well-established DDoS playbook to call upon when an incident occurs. Appropriately skilled personnel should be called upon to ensure the best level of protection and mitigation.

Last edited: 17 February 2020 11:29 am