P2P 봇넷 Panchan, Linux 서버 공격

Akamai reports that in March 2022, ㅏ new P2P botnet Panchan appeared, which targets Linux servers (mainly in the educational sector) and mines cryptocurrency.

Let me remind you that we wrote that Operators of the Clipminer Botnet “획득” More Than $1.7 백만, 그리고 그것도 61% of malicious ads target Windows users.

Panchan is written in Go and has the functionality of an SSH worm, 그건, it can perform dictionary attacks and abuse SSH keys to quickly move sideways on a compromised network.

사실은, Panchan infects new hosts by finding and using existing SSH keys, as well as by brute force logins and passwords. After success at this stage, it creates a hidden folder in which it hides under the name xinetd.

The malware then executes the binary and initiates an HTTPS POST to the Discord webhook, which is likely used to track the victim.

To gain a foothold in the system, Panchan copies itself to /bin/systemd-worker and creates a new systemd service to start after a reboot, 그건, it disguises itself as a normal system service.

P2P 봇넷 판찬

On the infected system, Panchan deploys and runs two miners, XMRig 그리고 nbhash, and the miners are not extracted to disk so as not to leave traces.

To avoid detection and reduce the likelihood of being tracked, malware deploys cryptominers as memory-mapped files, without any presence on disk. Panchan also eliminates mining processes if it detects signs of monitoring.the analysts write.

It is reported that in total, researchers were able to detect 209 peers in the Panchan P2P network, although only 40 of them are currently active, and these systems are mainly located in Asian countries.

The researchers say that most of the victims are related to the education sector, which matches the methods of distribution of malware and facilitates the growth of botent. The fact is that when conducting international academic research, ideal conditions are created for the spread of malware, because such projects are characterized by poor “digital hygiene” in the field of passwords and the sharing of SSH keys.

저자 소개

카리나 윌슨

이상으로 10 온라인 및 인쇄 매체에 대한 수년간의 글쓰기 경험, 나는 명확하고 매력적인 카피를 제공하는 전문가입니다..

최고의 SEO 카피라이팅 에이전시와 영국에서 가장 잘 알려진 브랜드를 위해 글을 썼습니다., 잡지와 신문.

코멘트를 남겨주세요