Site navigation

DemonBot Discovered Harvesting Hadoop Systems

Duncan MacRae

,

The DemonBot botnet is being spread by more than 70 active exploit servers, according to a Radware investigation.

A botnet dubbed DemonBot, which is actively looking for unsecured Hadoop systems, has been discovered by security firm Radware.

According to Radware, there are more than 70 active exploit servers spreading DemonBot. The bot attack spreads from a central server rather than a worm attack that spreads from one host to the next.

Pascal Geenens, Radware’s EMEA cyber-security evangelist, told e-week.com: “Given the size of Hadoop servers, we expect some very capable servers with good connectivity, so the attacks might be considerably large.

Malicious activities

Botnet operators want to infect systems, thereby enlisting them to launch other malicious activities. Some botnets, such as the Mirai IoT botnet that started infecting systems towards the end of 2016, actively scan for vulnerable systems in an effort to accelerate exploitation. DemonBot works differently, according to Radware.

Geenens said: “Since DemonBot does not expose any scanning behaviour, it does not make noise like traditional IoT botnets that use distributed scanning.

“Hence, it is not possible for us to map out the location of infected servers without resorting to illegal access of the command and control servers.”

Radware is gathering more information by identifying potentially vulnerable servers and plans to cross-correlate with the distributed denial-of-service (DDoS) attack information from the company’s Cloud DDoS service in order to determine scope and impact.

Although DemonBot could potentially be used for large-bandwidth DDoS attacks, Greenens noted that Radware is not just concerned about the large attacks. Instead, Radware is primarily concerned with daily attacks that may not be record breaking in terms of attack volume, but still have a big impact on many organisations.

Greenens said: “Most of the customers are easily saturated with attacks starting at just a couple of Gbps. A botnet of just 2G bps is a powerful weapon that can cause a lot of damage. It does not have to be 1T-bps+ botnet.”

Radware discovered DemonBot through the use of a deception network, consisting of multiple layers, with the first layer monitoring attacks on any port and for any service but does not respond to queries.

https://www.digitexpo.uk/

Greenens said: “Once we detected the pattern, we investigated the origin of the request. Based on the proof of concept code for the vulnerability, we set up a dummy service that listens on port 8088 and replies to queries for YARN new-application with an application-id, at which point the exploit server makes a second request with the command and the location of the malware.”

Any Hadoop cluster with YARN (Yet Another Resource Manager) enabled and exposed on the internet through port 8088 is potentially at risk from DemonBot, Greenens explained. YARN provides application and cluster management capabilities for Hadoop big data deployments.

In order for companies to prevent themselves being drawn into the DemonBot botnet, Greenens said: “If there is no need to have YARN exposed on the internet, do not expose it.

“If you need to expose it for some reason, do so with care and protect it using authentication and strict permissions. It is, after all, a web API, and there are many ways to secure access to web APIs through API gateways.”

Duncan MacRae

Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data