{"id":2159,"date":"2023-12-07T18:53:00","date_gmt":"2023-12-07T18:53:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/headcrab-malware-variants-commandeer-thousands-of-servers"},"modified":"2023-12-07T18:53:00","modified_gmt":"2023-12-07T18:53:00","slug":"headcrab-malware-variants-commandeer-thousands-of-servers","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/12\/07\/headcrab-malware-variants-commandeer-thousands-of-servers\/","title":{"rendered":"&#8216;HeadCrab&#8217; Malware Variants Commandeer Thousands of Servers"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta6a97ea9c29445f3\/65708e7350e45a040a54ab79\/headcrab_aqua_Dan_Raywood_Black_Hat.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BLACK HAT EUROPE 2023 \u2014 London \u2014 The HeadCrab malware, which adds infected devices to a botnet for use in cryptomining and other attacks, has resurfaced with a shiny new variant that allows root access to Redis open source servers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers from Aqua Security said the second variant of cryptomining malware has infected 1,100 servers; the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/blog.aquasec.com\/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">first variant<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> had already infected at least 1,200 servers.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">The Root to Redis?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security researcher Asaf Eitani, who is part of Team Nautilus, Aqua Security&#8217;s research team, tells Dark Reading that while HeadCrab is not a traditional rootkit, the creator of the malware has added the ability for it to control a function and send a response.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Basically, that&#8217;s a rootkit behavior in the sense that he controls all the responses for those places,&#8221; Eitani says. &#8220;So he can just modify the response and become invisible.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Eitani adds, &#8220;The tradition of the term <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.malwarebytes.com\/rootkit\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">rootkit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is malware that has root access and controls everything, but in this sense you are able to control what the user sees.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Second Variant<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The new variant comes with minor updates that allow an attacker to better hide their actions by removing custom commands and adding encryption to the command and control infrastructure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;[We believe] he is still modifying it, and we expect to find a newer version of this malware and to see the way the way that he reacts to our publication [of further details],&#8221; Eitani says. &#8220;He has not given up.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Details of both variants were shared today in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.blackhat.com\/eu-23\/briefings\/schedule\/index.html#rediscovering-headcrab---a-technical-analysis-of-a-novel-malware-and-the-mind-behind-it-34310\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">presentation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Eitani and his colleague, senior data analyst Nitzan Yaakov.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Talking Back<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A particularly unique element of HeadCrab is a &#8220;mini blog&#8221; inside the malware, where the malware&#8217;s author wrote technical details of the malware and left a Proton Mail email address to remain anonymous.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Aqua Security researchers used the email to contact the HeadCrab creator \u2014 who went by the code name Ice9 \u2014 but were unable to determine his name or location. However, Ice9 told the researchers that they were the first people to email him.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In email conversations with the researchers, Ice9 said the malware does not reduce server performance, and can remove other malware infections. He also sent the researchers a hash of the malware so they could inspect it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After detecting the second variant, a new message in the mini blog from Ice9 praised the work the Aqua researchers did. &#8220;He also mentioned some technical details that we missed from the first version, and the last note was regarding technicalities in the new version and how he got rid of the custom commands,&#8221; Eitani says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ice9 is the only user of HeadCrab, and solely in control of the command and control infrastructure, Eitani notes.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Taking Control<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">HeadCrab infects a Redis server when the attacker uses the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/redis.io\/commands\/slaveof\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">SLAVEOF<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> command, downloads a malicious module, and runs two new files: a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cloud-security\/cryptojacking-freejacking-compromise-cloud-infrastructure\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">cryptominer<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and a configuration file. The process includes a command that allows administrators to designate a server within a Redis Cluster as a &#8220;slave&#8221; to another &#8220;master&#8221; server within the cluster, according to the researchers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The researchers recommended that organizations scan for vulnerabilities and misconfigurations in their servers, and use protected mode in Redis to reduce the chance for infection from HeadCrab.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/headcrab-malware-variants-commandeer-thousands-of-servers\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BLACK HAT EUROPE 2023 \u2014 London \u2014 The HeadCrab malware,<\/p>\n","protected":false},"author":12,"featured_media":2160,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?fit=2560%2C1928&ssl=1",2560,1928,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?fit=300%2C226&ssl=1",300,226,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?fit=640%2C482&ssl=1",640,482,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?fit=640%2C482&ssl=1",640,482,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?fit=1536%2C1157&ssl=1",1536,1157,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?fit=2048%2C1542&ssl=1",2048,1542,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?fit=1024%2C771&ssl=1",1024,771,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/headcrab-malware-variants-commandeer-thousands-of-servers-scaled.jpg?fit=2560%2C1928&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2159"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2159\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2160"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}