Tuesday, February 27, 2024

Hackers Used Default/weakest Credentials for IoT Botnet Command and Control Server

Hackers used default Username: root, Password: root for their IoT botnet command and control server.

IoT botnet Owari relies on default/ weak credentials to hack IoT devices uses a MySQL server for command and control that allows attackers to maintain communications with compromised systems.

NewSky Security researcher Ankit Anubhav observed that their honeypot with default credentials attacked by OWARI bot and attempts to download payload form IP 80[.]211[.]232[.]43.

Also Read Secure Cloud Migration Guide – Technical and Business Considerations

With their further investigation on attack IP 80[.]211[.]232[.]43, it was identified that default MySQL server port 3306 was open and unexpectedly the server contains the default and weakest credential that every computer user know.

Username: root
Password: root

Ankit Anubhav said the database contains the login credentials of users who control’s the database and the time duration limit for users to utilize the bot for the DDoS attack.

“Some of them can be botnet creators or some can simply be the customers of the botnet, a.k.a black box users, who pay a sum of money to launch DDoS attacks.”

Ankit Anubhav points out that history tables show that bot has been used to launch a DDoS attack against various IP address and the next table is whitelist which contains no Ip address.

IoT botnet Owari

“This IP was not a standalone case with its database exposed via weak credentials. The MySQL database of another attack IP 80[.]211[.]45[.]89 was accessible with “root: root” credentials.”

He concluded that both IP’s are offline now, they aware “their IPs will be flagged soon due to the bad network traffic” and “to stay under the radar, they often voluntarily change attack IPs.”


Latest articles

ThreatHunter.ai Stops Hundreds of Attacks in 48 Hours: Fighting Ransomware and Nation-State Cyber Threats

The current large surge in cyber threats has left many organizations grappling for security...

WordPress Plugin Flaw Exposes 200,000+ Websites for Hacking

A critical security flaw has been identified in the Ultimate Member plugin for WordPress,...

Hackers Actively Hijacking ConnectWise ScreenConnect server

ConnectWise, a prominent software company, issued an urgent security bulletin on February 19, 2024,...

Heavily Obfuscated PIKABOT Evades EDR Protection

PIKABOT is a polymorphic malware that constantly modifies its code, making it hard to...

Anonymous Sudan Promoting New DDoS Botnet: Beware

It has come to light that a group known as Anonymous Sudan is actively...

Scattered Spider: Advanced Techniques for Launching High-Profile Attacks

Scattered Spider is a threat group responsible for attacking several organizations since May 2022...

8220 Hacker Group Attacking Linux & Windows Users to Mine Crypto

In a significant escalation of cyber threats, the 8220 Gang, a notorious Chinese-based hacker group, has intensified its attacks...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Live Account Takeover Attack Simulation

Live Account Take Over Attack

Live Webinar on How do hackers bypass 2FA ,Detecting ATO attacks, A demo of credential stuffing, brute force and session jacking-based ATO attacks, Identifying attacks with behaviour-based analysis and Building custom protection for applications and APIs.

Related Articles