February 23, 2017 By Larry Loeb 2 min read

The recently observed Mirai botnet spreader that uses Windows systems as its launching pad has caused some consternation in security circles. This week, Russian-based Kaspersky Lab issued a report on the phenomenon that looked at the specifics of the malware for some insight as to its origin and function.

Mirai Botnet Code Contains Crucial Clues

Security researchers stressed that what they have seen since January is just spreader malware that uses a different platform, not a new botnet. It attempts to brute-force a remote Telnet connection to spread Mirai to resources that would have otherwise been unavailable. The actual botnet still needs an embedded Linux system to operate.

SecurityWeek reported that some spreader components date back as far as 2014, and the functionality of invasive SQL attacks can be traced back to public sources as early as 2013. Meanwhile, the Kaspersky report noted that one of the directly related web command-and-control (C&C) hosts has been serving bot components since at least August 2014.

However, interesting clues emerged when the researchers analyzed the spreader’s code. Kaspersky experts called the code “richer and more robust than the Mirai codebase, with a large set of spreading techniques, including brute-forcing over Telnet, SSH, WMI, SQL injection and IPC techniques.”

Digging to China

Researchers also looked at multiple artifacts in the code, such as the word choices of string artifacts, and found that the code was compiled on a Chinese system. Additionally, the host servers were maintained in Taiwan and the operators abused code-signing certificates stolen from Chinese companies. These discoveries led the researchers to conclude that the attackers speak Chinese.

The report noted that the bot variant code and its components “have been pulled together from other projects and previous sources.” For example, components are embedded within JPEG file comments, a technique that has been used since 2013. This can provide the bot with very large file objects.

Kaspersky concluded that this spreader shows the development process going on around Mirai. It is changing from a pure destructive effort to a display of sophisticated propagation and intrusion capabilities. Security professionals will need to keep a keen eye on this malware in the future as it evolves further.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today