Pink's botnet infected over 1,600,000 devices

Brother

Professional
Messages
2,565
Reputation
3
Reaction score
362
Points
83
12bea5e6151ad2d099828.png

The Netlab Qihoo 360 research team says it has discovered the "largest botnet" in the past six years. Malware Pink has already infected more than 1.6 million devices, mostly located in China (96%).

These bots are used by botnet operators for DDoS attacks and injecting ads on HTTP sites. It is reported that at least 100 DDoS attacks have been carried out by the botnet to date.

botnet.jpg


According to experts, Pink has been active since November 2019. The malware mainly attacks MIPS routers and uses various third-party services, including GitHub, as well as P2P and centralized C&C servers to connect bots with operators and transfer commands. Pink also uses DNS-Over-HTTPS to connect to the server specified in the configuration file, which is either delivered via GitHub or Baidu Tieba (sometimes the domain name is completely hardcoded).

"Pink's operators fought with the supplier to control the infected devices: while the supplier made repeated attempts to fix the problem, the master bot detected the supplier's actions in real time and repeatedly updated the firmware of the routers accordingly," the analysts say.
According to another Chinese company, NSFOCUS, the malware spreads through the exploitation of 0-day vulnerabilities in network devices. And although today a significant proportion of such devices have been fixed and restored to their previous state, the botnet is still active and consists of no less than 100,000 devices.
 
Top