Zhadnost Botnet
Summary
Attribution of the malware to a specific threat actor has not been possible with the currently available information, but it is rather likely that the cybercrime organization responsible for the botnet has ties to Russia. The majority of the compromised devices are MikroTik routers that were breached through misconfigured DNS recursion settings or other vulnerabilities. The bots were then instructed to launch DDoS attacks through HTTP floods and DNS amplification. As Russia becomes more aggressive and ruthless in its actions against Ukraine, cybersecurity experts expect that its efforts to disrupt key websites and digital platforms also would intensify. This could mean that despite the lack of impact from the current operations involving the Zhadnost botnet, the malware could be leveraged in more precise attacks against critical targets, such as power generators, telecommunication services, military units, etc.