By Attacking Healthcare, Education, and Government Systems, FritzFrog Botnet Grew Tenfold

This article has been indexed from

CySecurity News – Latest Information Security and Hacking Incidents

 

The FritzFrog botnet, which has been active for over two years, has revived with an alarming infection rate, growing tenfold in just a month of attacking healthcare, education, and government networks via an unprotected SSH server. FritzFrog, a malware developed in Golang that was discovered in August 2020, is both a worm and a botnet that targets the government, education, and finance sectors. 
The malware fully assembles and executes the malicious payload in memory, making it volatile. Furthermore, because of its unique P2P implementation, there is no central Command & Control (C&C) server giving commands to FritzFrog. It is self-sufficient and decentralised. Despite FritzFrog’s harsh brute-force tactics for breaching SSH servers, it is strangely efficient at targeting a network equitably. 
Guardicore Labs has been monitoring FritzFrog with its honeypot network for some time. “We started monitoring the campaign’s activity, which rose steadily and significantly with time, reaching an overall of 13k attacks on Guardicore Global Sensors Network (GGSN). Since its first appearance, we identified 20 different versions of the Fritzfrog binary,” said the company in a report published in August 2020, authored by security researcher Ophir Harpaz.
Researchers at internet security firm Akamai discovered a new version of the FritzFrog malware, which has intriguing new features such as the use of the Tor proxy chain. The new botnet variation also reveals signs of its operators planning to enhance capabili

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: