Outlaw IRC Botnet
Two new variants of the Outlaw hacking group's botnet have been observed. The Outlaw botnet targets organisations worldwide and is based on the Shellbot remote access trojan.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Two new variants of the Outlaw hacking group's botnet have been observed. The Outlaw botnet targets organisations worldwide and is based on the Shellbot remote access trojan.
Affected platforms
The following platforms are known to be affected:
Threat details
It uses a complex IRC-based command and control infrastructure to deliver different variants of the bot to devices depending on their configuration.
The first variant of the botnet is used for cryptocurrency mining and for further discovery of new devices. Once installed on a Linux or Android device, it will terminate competing mining applications before downloading the XMRig mining module. Certain versions of this variant are able to hijack mining applications or wallets that are already present on a device. It will also use the haiduc (Romanian for dropper) tool to scan for new devices and perform brute-force attacks against them to propagate.
The second variant is focused on Microsoft devices and uses a hard-coded list of servers with the libc.so.6 library to supply new targets for the botnet. haiduc is then used to locate them and deploy exploits to gain access to. It will then use Remote Desktop Protocol (RDP) and cPanel exploits to escalate its privileges, propagate internally and collect system information.
For further information:
Update
The Outlaw botnet has been update so that it can perform distributed denial-of-service attacks.
Remediation steps
| Type | Step |
|---|---|
|
If Remote Desktop Protocol (RDP) is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:
To prevent and detect an infection, ensure that:
|
CVE Vulnerabilities
Last edited: 17 February 2020 1:00 pm