Muhstik Malware
Summary
The Muhstik botnet, notorious for its distributed Denial-of-Service (DDoS) attacks, has been spotted exploiting a recently patched vulnerability in Apache RocketMQ. This vulnerability enables remote, unauthenticated attackers to execute arbitrary code by manipulating RocketMQ protocol content or exploiting the update configuration feature. After exploiting this vulnerability to gain initial access, threat actors execute a shell script hosted on a remote IP address. The ultimate aim of this malware is to enlist compromised devices in various flooding attacks against specific targets, effectively inundating their network resources and causing denial-of-service disruptions. These activities complement each other as attackers seek to proliferate and infect more machines, aiding in their cryptocurrency mining endeavors by utilizing the computational power of compromised devices.