DemonBot DDoS Botnet
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The threat actors operating DemonBot are scanning the internet for Hadoop installations with misconfigured YARN modules. Attackers are actively exploiting a remote code execution vulnerability to access internal YARN APIs that are exposed to external connections. DDoS-capable malware strains can then be deployed inside Hadoop server clusters.
At the time of publication, DemonBot does not appear to be performing any malicious activity on infected devices. It is probable that the threat actors operating the botnet are attempting to limit discovery and analysis as it continues to grow.
Remediation steps
Last edited: 17 February 2020 12:41 pm