Cyber security researchers have identified a new form of malware that targets IOT devices and routers. Written in the programming language Golgang, BotenaGo can exploit over 30 vulnerabilities within the code of many IOT devices.
Due to its difficulty to detect, it’s thought that the malware may have already infected a large number of devices which, if true, could cause some serious problems for users. The researchers stated that it has the potential to exploit millions of devices, so it’s important that security teams be as prepared as possible if their network includes routers and IOT devices.
How does BotenaGo infect devices?
The malware works by creating a backdoor to the device. Once this has been created, it lies dormant within the system until a remote operator provides a target for the malware to attack. It can also be triggered by something else in the system, such as other malware or a related module.
To initially create the backdoor to the device, it explores a variety of networks to see if any devices might be vulnerable to an attack. Once it identifies a viable network or set of networks, it initialises global infection counters and lets the attack know how many of these devices it was able to infect.
The malware fundamentally revolves around loading shell script files into the ‘dlrs’ folder. If this isn’t present within the network or device, it is unable to infect it. This has been identified as a possible of preventing infections.
How does BotenaGo initiate attacks once it has infected a device or network?
Once in place within the network or device, there are two ways that the malware can proceed with an attack. Firstly, it can forcibly create extra backdoors through ports, allowing an attacker to breach the network in a variety of ways.
Secondly, it can receive an attack command by setting a listener to system IO user input. This allows it to get a command to the router or IOT device it wants to target.
How dangerous is BotenaGo for organisations?
For many organisations, this new and invasive malware poses a serious risk. As well as targeting IOT devices and routers, which if attacked could cause service problems and severe outages, BotenaGo can allow attackers to gain access to sensitive networks through the vulnerabilities in these devices.
By gaining access this way, an attacker can explore and exploit internal networks that may contain sensitive information. This opens up more avenues for potentially disastrous data breaches, leading to reputational damage, service outages, and regulatory fines.
Given the number of vulnerabilities that BotenaGo can exploit, organisations must keep their IOT devices and routers up to date with the latest firmware and patches. This greatly reduces the chance that this malware can infect it and open up sensitive networks for an attack.
How can an organisation prevent this malware from infecting them?
As we already mentioned, updating firmware and patching your IOT devices and routers is the best place to start. It’s also important for organisations to regularly assess their networks for vulnerabilities and weaknesses.
Penetration testing, compromise assessment, and cyber security reviews are the perfect way to assess your cyber security readiness. It’s highly advisable to undertake these reviews annually but depending on your organisation it may be necessary to do this more often. Ultimately, proactivity is the main way of preventing infections and the risk of cyber-attacks.
Source: Millions of Routers, IoT Devices at Risk from BotenaGo Malware | Threatpost


