On The Insider: Heidi Klum Takes Seal's Name
BNET Business Network:
BNET
TechRepublic
ZDNet

March 23rd, 2009

Stealthy router-based botnet worm squirming

Posted by Ryan Naraine @ 11:12 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Hackers, Open source, Passwords, Vulnerability research

Tags: Router, Worm, Cyberthreats, Routers & Switches, Viruses And Worms, Network Technology, Security, Networking, Ryan Naraine

Researchers at DroneBL have spotted signs of a stealthy router-based botnet worm targeting routers and DSL modems.

The worm, called “psyb0t,” has been circulating since at least January this year, infecting vulnerable embedded Linux devices such as the Netcomm NB5 ADSL modem (above) and launching denial-of-service attacks on some Web sites.

Some characteristics:

  • It’s the first botnet worm to specifically target routers and DSL modems
  • Contains shellcode for many mipsel devices
  • It’s not targeting PCs or servers
  • Uses multiple strategies for exploitation, including brute-force username and password combinations
  • Harvests user names and passwords through deep packet inspection
  • can scan for exploitable phpMyAdmin and MySQL servers

According to this DroneBL blog post, the worm can infect any Linux mipsel routing device that has the router administration interface or sshd or telnetd in a DMZ, which has weak username/passwords (including openwrt/dd-wrt devices).

The group estimates there are 100,000 hosts infected with this malware.

The author of this worm has some sophisticated programming knowledge, given the nature of this executable.

Action must be taken immediately to stop this worm before it grows much larger.

We came across this botnet as part of an investigation into the DDoS attacks against DroneBL’s infrastructure two weeks ago, and feel that this botnet was the one which flooded DroneBL.

There are suspicions this might be a proof-of-concept research project.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 27 Talkback(s)
but...
didn't you know Loverock is rubber, and you're glue, so whatever you say bounces off of him and sticks to you?

Geez, get a clue. And Loverock doesn't wear a helmet anymore, now that they've fin... (Read the rest)
Posted by: pgit Posted on: 09/30/09 You are currently: a Guest | | Terms of Use
And there are SOOO many routers with default "admin" password out there!  kd5auq | 03/23/09
I suggested this years ago.  TripleII | 03/23/09
They have to use a default password  Lerianis | 03/23/09
It is a default.  TripleII | 03/23/09
How many have WAN access by default?  TripleII | 03/23/09
All DSL Routers!(nt)  ShadeTree | 03/23/09
LOL, yes, brain fart on my part. (nt)  TripleII | 03/23/09
RE: Stealthy router-based botnet worm squirming  Loverock Davidson | 03/23/09
Lovey....3.0 on the comments???  MGP2 | 03/23/09
Ignorance exposed!  djchandler | 03/23/09
He has a problem of comprehension  deaf_e_kate | 03/24/09
And yet you didn't address any of his points.  ye | 03/24/09
Its not ignorance  Loverock Davidson | 03/24/09
Jeez...  ignatz_z | 03/24/09
Like I said before, its not ignorance  Loverock Davidson | 03/24/09
Hey Dorkrock Davidson  i8thecat | 03/24/09
but...  pgit | 09/30/09
"weak username/passwords" Your hubris knows no bounds  invmgr@... | 09/30/09
Not again.....  linux for me | 03/23/09
I imagine these type of worms may be long lived...  storm14k | 03/24/09
RE: Stealthy router-based botnet worm squirming  ptv5 | 03/24/09
Thus far it is iffy  kd5auq | 03/24/09
Also there is a firmware update for this.  phatkat | 03/24/09
netcomm again  walkerjian@... | 03/25/09
it still won't work  walkerjian@... | 03/25/09
RE: Stealthy router-based botnet worm squirming  the_hunteroz | 03/25/09
Any time I want Wi-Fi  oldbaritone | 03/27/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline