NoaBot Botnet
Summary
NoaBot boasts features such as a self-spreading worm and an SSH key backdoor, enabling the download and execution of supplementary binaries or the propagation to fresh targets. This widespread availability of the source code contributed to an increase in the number and scale of IoT-related attacks, posing significant challenges to cybersecurity professionals and device manufacturers. The basis for this connection lies in the observation that threat actors have experimented with substituting P2PInfect for NoaBot in recent attacks on SSH servers, hinting at potential efforts to transition to custom malware. Despite NoaBot being rooted in Mirai, its spreader module employs an SSH scanner to identify servers vulnerable to dictionary attacks, allowing it to conduct brute-force attempts. In addition to employing obfuscation tactics to complicate analysis, the attack sequence ultimately culminates in the deployment of a modified version of the XMRig coin miner.