Researchers ‘Accidentally’ Crash KmsdBot Cryptocurrency Mining Botnet Network

Share:

An ongoing analysis into an up-and-coming cryptocurrency mining botnet known as KmsdBot has led to it being accidentally taken down.

KmsdBot, as christened by the Akamai Security Intelligence Response Team (SIRT), came to light mid-November 2022 for its ability to brute-force systems with weak SSH credentials.

The botnet strikes both Windows and Linux devices spanning a wide range of microarchitectures with the primary goal of deploying mining software and corralling the compromised hosts into a DDoS bot.

 

Some of the major targets included gaming firms, technology companies, and luxury car manufacturers.

Akamai researcher Larry W. Cashdollar, in a new update, explained how commands sent to the bot to understand its functionality in a controlled environment inadvertently neutralized the malware.

Bild56

“Interestingly, after one single improperly formatted command, the bot stopped sending commands,” Cashdollar said. “It’s not every day you come across a botnet that the threat actors themselves crash their own handiwork.”

This, in turn, was made possible due to the lack of an error-checking mechanism built into the source code to validate the received commands.

Specifically, an instruction issued without a space between the target website and the port caused the entire Go binary running on the infected machine to crash and stop interacting with its command-and-control server, effectively killing the botnet.

The fact that KmsdBot doesn’t have a persistence mechanism also means that the malware operator will have to re-infect the machines again and re-build the infrastructure from scratch.

“This botnet has been going after some very large luxury brands and gaming companies, and yet, with one failed command it cannot continue,” Cashdollar concluded. “This is a strong example of the fickle nature of technology and how even the exploiter can be exploited by it.”

https://thehackernews.com/2022/12/researchers-accidentally-crashed.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:30 pm, Jun 1, 2025
weather icon 21°C
L: 19° | H: 22°
overcast clouds
Humidity: 43 %
Pressure: 1013 mb
Wind: 14 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
19° | 22°°C 0 mm 0% 15 mph 71 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 10 mph 84 % 1019 mb 0 mm/h
Tue Jun 03 10:00 pm
weather icon
11° | 17°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
9° | 19°°C 0 mm 0% 13 mph 83 % 1010 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
11° | 15°°C 1 mm 100% 13 mph 97 % 1009 mb 0 mm/h
Today 4:00 pm
weather icon
17° | 19°°C 0 mm 0% 15 mph 42 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
16° | 17°°C 0 mm 0% 12 mph 48 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
15° | 15°°C 0 mm 0% 8 mph 71 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 13°°C 0 mm 0% 6 mph 84 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 5 mph 79 % 1016 mb 0 mm/h
Tomorrow 7:00 am
weather icon
11° | 11°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 48 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
19° | 19°°C 0 mm 0% 8 mph 31 % 1018 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,823.45
0.04%
Ethereum(ETH)
€2,195.83
-1.85%
Tether(USDT)
€0.88
0.00%
XRP(XRP)
€1.89
-1.10%
Solana(SOL)
€133.76
-2.37%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.166079
-2.25%
Shiba Inu(SHIB)
€0.000011
1.41%
Pepe(PEPE)
€0.000010
-0.94%
Peanut the Squirrel(PNUT)
€0.228122
2.33%
Scroll to Top