Gorilla Botnet Strikes with Over 300,000 DDoS Attacks in 100 Countries

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

New Botnet Malware “Gorilla” Unleashed: A Variant of Mirai Source Code

The cybersecurity world has a new threat on its hands with the emergence of the GorillaBot, a new botnet malware family that is causing chaos across the digital landscape. This variant of the infamous Mirai botnet source code has been wreaking havoc with over 300,000 attack commands issued in just a few weeks.

The cybersecurity firm NSFOCUS has been tracking the activities of GorillaBot since last month and has found that the botnet has been launching distributed denial-of-service (DDoS) attacks at an alarming rate. With an average of 20,000 attack commands being issued every day, the botnet has targeted a wide range of sectors including universities, government websites, banks, and gaming platforms in over 100 countries.

The primary weapons in GorillaBot’s arsenal are UDP flood, ACK BYPASS flood, Valve Source Engine (VSE) flood, SYN flood, and ACK flood attacks. These tactics allow the botnet to generate a massive amount of traffic by exploiting the connectionless nature of the UDP protocol and carrying out arbitrary source IP spoofing.

What makes GorillaBot even more dangerous is its ability to exploit a security flaw in Apache Hadoop YARN RPC for remote code execution. This flaw has been exploited in the wild since 2021, highlighting the advanced capabilities of this new botnet malware.

To maintain control over infected devices, GorillaBot uses encryption algorithms commonly employed by the Keksec group and employs multiple techniques to avoid detection. With capabilities to support multiple CPU architectures and connect to predefined command-and-control servers, GorillaBot is proving to be a formidable adversary in the cybersecurity landscape.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cisco Patches Critical Nexus 9000 Vulnerability Allowing Remote Code Execution as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker...

BREEZE COMET Threat Actor Targets Brazilian Financial Sector with Sophisticated Attacks

BREEZE COMET: A Rising Threat to Brazil's Financial Sector In 2024, Mandiant began investigating a series of cyber compromises targeting Brazilian financial services, retail, and...

Dropbox Reports Compromise of 5,000 Accounts Due to Legacy Login Vulnerability

Dropbox has reported that approximately 5,000 accounts were compromised last month due to a legacy login vulnerability associated with Lenovo IDs. This breach allowed...

Maine Teen Becomes First Minor Federally Charged for Crimes Linked to Violent Extremist Group 764

The FBI has announced that a 17-year-old from Maine is the first minor to be federally charged and adjudicated for crimes related to their...