Thursday, April 3, 2025
HomeBotnetWater Barghest Botnet Comprised 20,000+ IoT Devices By Exploiting Vulnerabilities

Water Barghest Botnet Comprised 20,000+ IoT Devices By Exploiting Vulnerabilities

Published on

SIEM as a Service

Follow Us on Google News

Water Barghest, a sophisticated botnet, exploits vulnerabilities in IoT devices to enlist them in a residential proxy marketplace by leveraging automated scripts to identify vulnerable devices from public databases like Shodan. 

When the device is compromised, the Ngioweb malware is installed in a stealthy manner, thereby establishing a connection to command-and-control servers. 

The infected device is rapidly registered as a proxy, often within 10 minutes, enabling immediate monetization through the proxy marketplace, which highlights the significant threat posed by Water Barghest to IoT security.

Automation by Water Barghest

It automates the process of exploiting vulnerable IoT devices, starting with acquiring n-day or zero-day exploits by using Shodan to identify vulnerable devices and their IP addresses, then launches attacks using data-center IP addresses.

Maximizing Cybersecurity ROI: Expert Tips for SME & MSP Leaders – Attend Free Webinar

Successful attacks lead to the installation of Ngioweb malware, which registers with a C&C server and connects to a residential proxy provider’s entry points. 

These compromised devices are then listed on a marketplace as residential proxies, generating revenue for Water Barghest. The threat actor maintains a consistent operation with multiple workers scanning for vulnerabilities and deploying malware.

Ngioweb, a versatile malware strain, first emerged in 2018 as a Windows botnet, leveraging the Ramnit Trojan for distribution, and evolved in 2019 to target Linux systems, particularly WordPress-powered web servers, exploiting vulnerabilities in the platform or its plugins. 

 Ngioweb’s main function

The malware, utilizing a two-stage C&C infrastructure and a custom binary protocol, demonstrates its adaptability and potential for widespread impact across diverse operating systems and web applications. 

Then initializes function pointers dynamically, ignores signals, renames itself to mimic a kernel thread, closes standard file descriptors, disables the kernel watchdog, reads the device’s machine ID, decrypts its configuration using AES-256-ECB, and generates and resolves DGA domains for C&C communication. 

 File downloaded from second-stage C&C

Ngioweb malware is a trojan that infects devices and turns them into rotating proxies by using a two-tier C2 architecture to communicate with the attackers. 

The first stage C2 server provides configuration parameters like DGA seed, count, and C&C URL path uses DNS TXT requests to retrieve additional data from the C2 server

While the second-stage C2 server provides commands like CONNECT, CERT, and WAIT and also downloads a large file to estimate the victim’s bandwidth before selling the victim’s IP address on a residential proxy marketplace.  

 Residential proxy marketplace’s website

According to Trend Micro, a residential proxy marketplace is offering access to a large number of infected IoT devices for rent, which, compromised by Ngioweb malware, are rapidly added to the marketplace after infection. 

The marketplace operates a backconnect proxy infrastructure, allowing users to route traffic through the infected devices, which enables malicious actors to anonymize their activities and evade detection. 

The increasing availability and affordability of such services poses significant challenges for security professionals, highlighting the urgent need for improved IoT device security and network hardening to mitigate these threats.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN -> Try for Free

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Latest articles

Secure Ideas Achieves CREST Accreditation and CMMC Level 1 Compliance

Secure Ideas, a premier provider of penetration testing and security consulting services, proudly announces...

New Phishing Campaign Targets Investors to Steal Login Credentials

Symantec has recently identified a sophisticated phishing campaign targeting users of Monex Securities (マネックス証券),...

UAC-0219 Hackers Leverage WRECKSTEEL PowerShell Stealer to Extract Data from Computers

In a concerning development, CERT-UA, Ukraine's Computer Emergency Response Team, has reported a series...

Hunters International Linked to Hive Ransomware in Attacks on Windows, Linux, and ESXi Systems

Hunters International, a ransomware group suspected to be a rebrand of the infamous Hive...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

New Phishing Campaign Targets Investors to Steal Login Credentials

Symantec has recently identified a sophisticated phishing campaign targeting users of Monex Securities (マネックス証券),...

UAC-0219 Hackers Leverage WRECKSTEEL PowerShell Stealer to Extract Data from Computers

In a concerning development, CERT-UA, Ukraine's Computer Emergency Response Team, has reported a series...

Hunters International Linked to Hive Ransomware in Attacks on Windows, Linux, and ESXi Systems

Hunters International, a ransomware group suspected to be a rebrand of the infamous Hive...