Cayosin DDoS Botnet
Cayosin is a newly observed botnet as-a-service that combines elements of Mirai, Qbot and other publicly available software. The developer of Cayosin has been marketing the service through legitimate social media platforms.
Summary
Cayosin is a newly observed botnet as-a-service that combines elements of Mirai, Qbot and other publicly available software. The developer of Cayosin has been marketing the service through legitimate social media platforms.
Threat details
Cayosin looks to exploit vulnerabilities in Linux-based web servers, Internet-of-Things (IoT) devices and routers. Once installed, Cayosin will begin communicating with a command and control server.
Whilst Cayosin has primarily been used to launch distributed denial-of-service attacks, the service continues to evolve and is beginning to see use as a tool for other functions, including exfiltrating sensitive information and stealing credentials.
Remediation steps
| Type | Step |
|---|---|
|
To avoid devices becoming part of an IoT botnet, organisations should:
To protect against a distributed denial-of-service (DDoS) attack, organisations should ensure:
Should an organisation suspect it is subject to an active DDoS attack, they should ensure that every effort is made to stop the attack and restore service. However, care should be taken to ensure that the attackers are not using the DDoS attack as a distraction whilst other, potentially more sensitive, systems are exploited. Monitoring of critical systems is recommended, including the use of host-based intrusion prevention and detection systems (HIPS/HIDS) where appropriate. |
Last edited: 11 January 2022 9:43 am