Skip to main content

Outlaw IRC Botnet

Two new variants of the Outlaw hacking group's botnet have been observed. The Outlaw botnet targets organisations worldwide and is based on the Shellbot remote access trojan.

Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Two new variants of the Outlaw hacking group's botnet have been observed. The Outlaw botnet targets organisations worldwide and is based on the Shellbot remote access trojan.


Threat details

It uses a complex IRC-based command and control infrastructure to deliver different variants of the bot to devices depending on their configuration.

The first variant of the botnet is used for cryptocurrency mining and for further discovery of new devices. Once installed on a Linux or Android device, it will terminate competing mining applications before downloading the XMRig mining module. Certain versions of this variant are able to hijack mining applications or wallets that are already present on a device. It will also use the haiduc (Romanian for dropper) tool to scan for new devices and perform brute-force attacks against them to propagate.

The second variant is focused on Microsoft devices and uses a hard-coded list of servers with the libc.so.6 library to supply new targets for the botnet. haiduc is then used to locate them and deploy exploits to gain access to. It will then use Remote Desktop Protocol (RDP) and cPanel exploits to escalate its privileges, propagate internally and collect system information.

For further information:

Update  

The Outlaw botnet has been update so that it can perform distributed denial-of-service attacks.


Remediation steps

Type Step

If Remote Desktop Protocol (RDP) is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:

  • Only allow access for authorised RDP users.
  • Enforce strong password policies.
  • Enforce multi-factor authentication.
  • Don't allow RDP access for privileged user accounts.
  • Don’t use generic accounts.
  • Set user accounts with an expiry date.
  • Audit user accounts periodically.
  • Only allow point-to-point connections from specific IP addresses where feasible.
  • Ensure Transport Layer Security (TLS) is up-to-date.
  • Log and monitor all RDP activity and investigate unusual behaviour.
  • Consider only allowing RDP for authorised virtual private network (VPN) connections.

To prevent and detect an infection, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • Regular anti-virus and security scans are performed on your organisation’s estate.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.


CVE Vulnerabilities

Last edited: 17 February 2020 1:00 pm