- kVmVv1556637494 - DDoS Botnet Attack Electrum That Takes 152,000 Hosts on its Control

Newly Emerging DDoS attack that targets one of the most popular bitcoin wallet Electrum and now it reaches the 12,000 infected hosts.

This DDoS Botnet rapidly growing and takes many hosts Under its control since April 24 when the number of infected machines in the botnet was just below 0,000 but its keep increasing and finally reaches the 152k hosts according to the online tracker report.

Electrum users are continuously targeting by a series of phishing attacks since last Dec 2018 and stolen over $4 million USD at current exchange rates.

Due to the weakness in the Electrum , attackers able to trick users into downloading a malicious version of the wallet from two different rogue projects were active on Github from around December 21 through December 27.

hxxps://github.com/electrum-project/electrum/releases/tag/3.4.1
hxxps://github.com/electrum-wallet/electrum/releases
- fakeupdate - DDoS Botnet Attack Electrum That Takes 152,000 Hosts on its Control
update

But developers behind the Electrum decided to exploit the same flaw in their own software in order to redirect users to download the latest patched version.

Later this incident, actors were started to attack the legitimate Electrum servers that lead to overwhelmed the vulnerable clients that connected to malicious nodes.

Researchers from Malwarebytes uncovered the two distribution campaigns (RIG exploit kit and Smoke Loader) that associate with this botnet dropping the ElectrumDoSMiner .

Along with this, another loader called Trojan.BeamWinHTTP also involved with this attack that downloading ElectrumDoSMiner from a remote server.

According to Malwarebytes report, “As can be seen in the VirusTotal graphs above and below, there are hundreds of malicious binaries that retrieve the ElectrumDoSMiner. We surmise there are probably many more infection vectors beyond the three we’ve uncovered so far”

- botnet - DDoS Botnet Attack Electrum That Takes 152,000 Hosts on its Control

Attackers mainly targeting the Asia Pacific region (APAC), especially most bots are located in Brazil and Peru.

You can follow us on LinkedinTwitterFacebook for daily updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

Hackers Offered IoT Botnet as Service “TheMoon” : Botnet-as-a-Service

Hackers Exploiting ThinkPHP Vulnerability To Expand Hakai and Yowai Botnets

New Hacking Group Outlaw Distributing Botnet to Scan The Network & Perform Cryptocurrency-Mining & Brute-Force Attack

Outlaw Hacking Group Using Command Injection Flow To Attack Organizations Network using Botnet via C&C Server





Source link

No tags for this post.

LEAVE A REPLY

Please enter your comment!
Please enter your name here