Por ocho años, La botnet Cereals existía con un solo propósito.: descargo anime

Botnet Cereals downloaded anime

The Cereals IoT botnet appeared in 2012, and reached its peak in 2015, when there were about 10,000 dispositivos infectados. All these eight years, the Cereals botnet only downloaded anime for its creator.

All this time, Cereals exploited only one vulnerability and attacked D-Link’s NAS and NVR, combining them into a botnet.

Durante muchos años, the botnet has eluded the attention of information security professionals, and now it has almost ceased to exist.

“The fact is that the vulnerable D-Link devices on which Cereals parasitized began to become obsolete and out of order, eso es, they are becoming smaller and smaller. Además, el ransomware Cr1ptT0r accelerated the decay of the botnet, which destroyed the competing malware on infected devices and removed the Cereals malware from many D-Link devices in the winter of 2019”, — say Forcepoint researchers.

Ahora, as the botnet and the vulnerable devices that it has exploited are disappearing, Forcepoint experts decided to publish a report on the activities of the malware, because they can no longer be afraid that the study will draw the attention of other criminals to vulnerable devices and provoke the emergence of new botnets.

Botnet Cereals downloaded anime

Experts write that Cereals can be called a unique phenomenon, since the botnet used only one vulnerability throughout all eight years of its “life”.

Éste vulnerabilidad was related to the SMS notification feature that was present in the D-Link NAS and NVR firmware. The bug allowed the creator of Cereals to send malicious HTTP requests to the embedded servers of vulnerable devices and execute commands with root privileges. De este modo, the botnet operator infected the devices with its malware.

“The botnet was very advanced in its functionality. Por lo tanto, if the attack succeeded, Cereals supported up to four active backdoors on the devices, tried to patch the attacked devices so that other attackers could not attack them, and distributed bots on 12 small subnets”, – dicen los investigadores.

Sin embargo, all these efforts, en realidad, were a waste of time. Forcepoint analysts believe that Cereals was someone else’s hobby or a project created as a joke (it is assumed that the author of the malware is called Stefan and he lives in Germany).

The fact is that the botnet did not engage in DDoS attacks, did not try to attack any other devices other than the above, did not try to access user data stored on infected devices. En cambio, all these years Cereals just methodically downloaded anime.

Sin embargo, this is the cutest botnet I talked about on this blogothers are mostly not like that, Por ejemplo, read an article about Hoaxcalls botnet, that attacks Grandstream devices.

Por Vladimir Krasnogolovy

Vladimir es un especialista técnico al que le encanta dar consejos y sugerencias cualificados sobre los productos de GridinSoft. Está disponible las 24 horas del día, los 7 días de la semana para ayudarte con cualquier pregunta relacionada con la seguridad en Internet.

Dejar un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *