Automatically translated.View original post

The Mirai malware has cracked more than 100 subspecies.

The Mirai malware has already cracked more than 100 subspecies.

Malware of the hacker-to-network type or Botnet is often used to implement infected machine networks in a mass attack or DDoS (Distributed Denial-of-Service). There are many malware like this, the most famous of which will not escape the Mirai that is currently evolving.

According to a report by the website, Hackread mentioned the expansion of Botnet malware, Mirai, which has developed more than 116 species, from examining 21,000 malware-contaminated files, of which Mirai malware was first detected in 2016. 2016) The malware will focus on devices for network management and IoT devices for use in DDoS attacks. This malware source code was later leaked to the hands of other hackers, bringing it to the breed this time.

Among the many breakaway species, there is an interesting one: Satori, which can spread to embedded in up to 260,000 routers by relying on security vulnerabilities on D-Link DSL-2750B routers. While another species of malware like KimWolf is focused on attacking devices running on a variety of Android operating systems - mobile phones to smart TV televisions - these malware are distributed to hackers as rental malware or MaaS (Malware-as-a-Service) through the trading channel on the famous chat app. Such as Discord or Telegram. In these channels, not only the two malware mentioned above are sold, but many other Mirai breakaway species, such as Aisuru, Tiny Mantis, Murdoc _ Botnet, Lzrd and Resgods, etc.

In the area of use to attack the system, the research team gave an example of the use of Aisuru and Kimwolf malware by the Aisuru-Kimwolf group. Using the malware, it mobilized the target system at an incredible speed of more than 31.4 terabit per second, sending more than 14.1 billion packages. This attack featured, in addition to being the largest attack on record, the package was random, making it difficult to detect and prevent from the fact that many of the system's security tools could not only see the package, but also the research team. It has been revealed that these hackers have used Proxy, a real IP Address server, or Residential Proxies like IPIDEA to hide themselves by impersonating the IP numbers of victims who are not involved in such attacks. Although the infrastructure of such hackers has been destroyed by law enforcement, the group itself has not been completely subdued. It has also moved itself into The Invisible Project's Hidden Network (I2P), making it even more difficult to detect.

# Trending # Lemon 8 Howtoo # lemon 8 diary # mirai # freedomhack

4/18 Edited to

... Read moreจากประสบการณ์การติดตามข่าวสารด้านความปลอดภัยไซเบอร์ ผมพบว่า มัลแวร์ Mirai ไม่เพียงแต่พัฒนาไปในเรื่องของจำนวนสายพันธุ์ย่อยเท่านั้น แต่ยังมีการปรับปรุงเทคนิคการโจมตีให้ซับซ้อนและหลบเลี่ยงการตรวจจับได้อย่างมีประสิทธิภาพมากยิ่งขึ้น การโจมตีด้วย DDoS ที่ใช้มัลแวร์ Mirai รุ่นใหม่ มักจะเป็นแบบใช้แพ็คเกจที่มีลักษณะสุ่มแทนที่จะแฮ็กแพ็คเกจจากแหล่งเดียว ทำให้ซอฟต์แวร์รักษาความปลอดภัยตรวจจับได้ยากขึ้น นอกจากนี้ การใช้ Proxy เซิร์ฟเวอร์ที่เป็น Residential Proxy ยังช่วยให้กลุ่มแฮกเกอร์สามารถซ่อนตัวตนและเลี่ยงการปิดกั้น IP ได้อย่างชาญฉลาด นอกจากนี้ ผู้ใช้งานทั่วไปที่มีอุปกรณ์ IoT หรือเราเตอร์ที่ไม่ได้รับการอัปเดตซอฟต์แวร์อย่างสม่ำเสมอ มีความเสี่ยงสูงมากที่จะถูกโจมตีจากมัลแวร์ Mirai ที่เลือกใช้ช่องโหว่ในอุปกรณ์เหล่านี้เป็นจุดเข้าถึง อย่างเช่นกรณีของเราเตอร์ D-Link รุ่น DSL-2750B ซึ่งถูกแพร่กระจายโดยสายพันธุ์ Satori ผมขอแนะนำว่า ควรเปลี่ยนรหัสผ่านของเราเตอร์และอุปกรณ์ IoT เป็นรหัสที่ซับซ้อนและไม่ใช้ค่าเริ่มต้น รวมถึงอัปเดตเฟิร์มแวร์ให้เป็นเวอร์ชันล่าสุด เพื่อลดช่องโหว่ที่มัลแวร์ Mirai หลายสายพันธุ์อาศัยโจมตี ท้ายที่สุด การติดตามข่าวสารจากทีมวิจัยด้านความปลอดภัยและหน่วยงานที่เกี่ยวข้องก็เป็นสิ่งจำเป็น เพื่อให้ทราบถึงภัยคุกคามและแนวทางป้องกันที่อัพเดตล่าสุด โดยเฉพาะอย่างยิ่งเมื่อมัลแวร์ Mirai ถูกจัดจำหน่ายในรูปแบบ Malware-as-a-Service หรือ MaaS บนแพลตฟอร์มต่างๆ อย่าง Discord และ Telegram ด้วยการตระหนักถึงภัยคุกคามและการลงมือป้องกันอย่างเหมาะสม เราสามารถรักษาความปลอดภัยบนโลกออนไลน์ได้อย่างมีประสิทธิภาพมากขึ้น ฝึกฝนการสังเกตและปฏิบัติตามหลักการรักษาความปลอดภัยไซเบอร์จะช่วยสร้างภูมิคุ้มกันให้กับระบบและอุปกรณ์ของเราได้อย่างมั่นคง