DDoS Botnet Controlled by Tweets
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The malware that is being used to infect compromised devices is being spread via a file named driversUpdate.exe. The Twitter account will be used to tweet out a coded message which the malware will detect and identify the command(s) to carry out. The commands that the malware will be looking for are:
wakeup – This tells the bot(s) to visit an IP address logger, which records the IP addresses of all the bots and determines the size of the botnet.
target – This command will start a DDoS attack against a specific target.
stop – This command will stop the DDoS attack.
dexe - This will download a specific file and execute it.
exe – This will execute CLI commands.
dl – This command is used to download a specific file, but will check beforehand if it already exists.
df – This command will do the same as ‘dl’, however, does not check if the file exists.
The malware’s source code shows a continued focus on creating new methods of carrying out DDoS attacks using public services such as social networks. With this method already working it does open opportunities for the malware author or others to build upon its capabilities.
Remediation steps
Last edited: 17 February 2020 11:29 am