Botnet of devices infected with Chaos malware ‘rapidly growing’ across Europe
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-17215 | Huawei HG532 with some customized versions has a remote code execution vulnerability. Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code. NVD description · AI analysis pending | 8.8 | 78% |
| — | ||
| CVE-2022-30525 | OS Command Injection in Zyxel Firewalls Enables Remote Command Execution CVE-2022-30525 is an OS command injection vulnerability (CWE-78) in the CGI program of certain Zyxel firewall firmware versions. By sending crafted requests to the vulnerable CGI program, an attacker can modify specific files on the appliance and inject and execute operating system commands. Successful exploitation yields command execution on the firewall itself, allowing an attacker to alter device files/configuration and potentially pivot into the protected network — the class of edge-device flaw commonly targeted by ransomware operators (ransomware use in this case is not yet confirmed). Organizations running affected Zyxel firewalls, particularly those with management interfaces reachable from the internet, are at risk. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-05-16, EPSS assigns a 99.9% 30-day exploitation probability (100th percentile), and no public PoC is catalogued yet. Do: Apply Zyxel's fixed firmware per the vendor's instructions immediately, as required by the CISA KEV listing. Until patched, restrict HTTP/HTTPS management access to the firewall to trusted source addresses only. Because exploitation is confirmed in the wild, prioritize internet-facing Zyxel firewalls and review devices for indicators of compromise such as modified configurations or unexpected administrative changes. | 9.8 | 100% | KEV PoC ×3 |
| large≈ tens of thousands of internet-exposed Zyxel firewall management interfaces (order of magnitude 10k–100k devices) |
Full article657 words · extracted from therecord.media · click to collapse
A multi-purpose malware written in the Go programming language is raising alarms among researchers worried about its spread in Europe. Lumen Technologies’ threat intelligence team — Black Lotus Labs — dubbed the malware “Chaos” and said it was built for Windows and Linux as well as a wide array of consumer devices, enterprise servers and small office/home office routers. Chaos is one of several examples of cybercriminals turning to the Go programming language when writing malware — the language is flexible to use, has low rates of antivirus detection and is difficult to reverse-engineer. The malware is allegedly an evolution of the DDoS malware Kaiji, which researchers highlighted in 2020. The latest additions include the ability to automatically exploit known vulnerabilities and provide its operators with ways to scan a target system, automatically move laterally and propagate through a system, launch DDoS attacks and initiate crypto-mining operations. “We are seeing a complex malware that has quadrupled in size in just two months, and it is well positioned to continue accelerating,” said Mark Dehus, director of threat intelligence for Lumen Black Lotus Labs. The researchers examined 100 samples of the malware. “Chaos poses a threat to a variety of consumer and enterprise devices and hosts. The Chaos malware targets known vulnerabilities.” In June, the researchers found several Chaos clusters that were written in Chinese and leveraging command and control infrastructure based in China, expanding further in the country throughout August and September. Black Lotus Labs found hundreds of unique IP addresses representing compromised Chaos bots from mid-June through mid-July, with most heavily concentrated in Europe. They also found bots in North and South America, as well as the Asia Pacific region. Since they first spotted 15 active nodes with similar self-signed certificates that contained the word “Chaos” in the organization name, the number has grown. By May it was at 39 and it hit 93 in August. As of September 27 it reached 111. “We observed interactions with these servers from both embedded Linux devices as well as enterprise servers, such as one in Europe that was hosting an instance of GitLab. Like the Chaos bots depicted in the heatmap above, the majority of the entities communicating with the staging servers were located in Europe with few devices distributed globally,” the researchers said. “Over the first few weeks of September, our Chaos host emulator received multiple DDoS commands targeting roughly two dozen organizations’ domains or IPs. Targeted entities included gaming, financial services and technology, media and entertainment, and hosting.” The report attributes Chaos to a cybercriminal group or individual that is intentionally cultivating a network of infected devices to leverage for initial access, DDoS attacks and crypto-mining for the Monero currency. While no current botnet infrastructure resembles past behemoths that could leverage more than 100,000 or 500,000 infected devices, Chaos has grown rapidly over the last few months, according to the researchers. Chaos is also distinct because the operators behind the malware can list out designated vulnerabilities it should target. At least one bot received more than 70 different commands over the course of a few days, according to the researchers. The vulnerabilities listed included one affecting Huawei – CVE-2017-17215 – and another affecting a Zyxel personal firewall: CVE-2022-30525. But the researchers noted that the CVE file appears “trivial” and that dozens of bugs are abused. The Chaos malware is also particularly harmful because it targets devices and systems that typically are not monitored by security systems. The CVE exploitation feature is a new addition to the capabilities of a malware that can be traced back to 2020. A growing botnet
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/botnet-of-devices-infected-with-chaos-malware-rapidly-growing-across-europe