{"id":3776,"date":"2024-05-28T16:01:11","date_gmt":"2024-05-28T21:01:11","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/catddos-threat-groups-sharply-ramp-up-ddos-attacks"},"modified":"2024-05-28T16:01:11","modified_gmt":"2024-05-28T21:01:11","slug":"catddos-threat-groups-sharply-ramp-up-ddos-attacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/28\/catddos-threat-groups-sharply-ramp-up-ddos-attacks\/","title":{"rendered":"CatDDOS Threat Groups Sharply Ramp Up DDoS Attacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt208b0527f6d30915\/66564145ea71f60221a09d43\/ddos_Photon_photo_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers have spotted a recent surge in activity involving a Mirai distributed denial-of-service (DDoS) botnet variant called CatDDoS.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attacks have targeted organizations across multiple sectors and include cloud vendors, communication providers, construction companies, scientific and research entities, and educational institutions in the US, France, Germany, Brazil, and China.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Multiple Variants\">Multiple Variants<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The malware first surfaced last August and was a relatively prolific threat in September 2023. CatDDoS dropped largely out of sight in December, prompting researchers tracking the threat at China&#8217;s QiAnXin XLab to assume the operators of the malware may have pulled its plug.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/ti.qianxin.com\/blog\/articles\/New-Generation-Botnet-CatDDoS-is-Evolving-Continuously-CN\/?ref=blog.xlab.qianxin.com\" rel=\"noopener\">report issued this week<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, QiAnXin said its researchers have observed multiple gangs using CatDDoS variants during the past three months. The operators of the variants, which are being tracked under various names, including RebirthLTD, Komaru, and Cecilio Network, have so far exploited at least 80 different vulnerabilities in their new campaign, QiAnXin said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Our system has observed that CatDDoS-related gangs remain active,&#8221; QiAnXin said in a blog post. &#8220;Additionally, the maximum number of targets has been observed to exceed 300+ per day.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The vulnerabilities being exploited under the CatDDoS umbrella affect dozens of products and technologies, including <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/attackers-target-max-severity-apache-activemq-bug-to-drop-ransomware\" rel=\"noopener\">Apache ActiveMQ Servers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/log4j-vulnerabilities-are-here-to-stay-are-you-prepared-\" rel=\"noopener\">Apache Log4j<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Cisco Linksys, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/poc-exploits-heighten-risks-around-critical-new-jenkins-vuln\" rel=\"noopener\">Jenkins<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> servers, and NetGear routers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many of the vulnerabilities are recent, meaning they were disclosed over the past year. But there are numerous others that CatDDoS threat actors are leveraging that are relatively old. Among them is <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2010-2506\" rel=\"noopener\">CVE-2010-2506<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a nearly 14-year-old vulnerability in Linksys firmware; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2013-1599\" rel=\"noopener\">CVE-2013-1599<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a more than decade-old flaw in D-Link IP cameras; and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2011-5010\" rel=\"noopener\">CVE-2011-5010<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a remote code execution vulnerability in Ctek SkySouters from 2011.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We have not yet identified some vulnerabilities, but it may be a zero-day vulnerability based on the parameters of execution of the samples,&#8221; QuAnXin said. &#8220;For example, &#8216;skylab0day&#8217; and &#8216;Cacti-n0day&#8217; are shown in the sample&#8217;s running parameters,&#8221; the company noted, pointing to CatDDoS-related telemetry that its researchers analyzed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to QuAnXin. CatDDoS actors have been compromising upward of 300 targets per day in the latest wave of attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The CatDDoS variants that the security vendor has observed all appear to be based on source code that the authors of the original malware publicly released in December after a futile bid to get someone to buy it off them. &#8220;Though the different variants may be managed by different groups, there is little variation in the code, communication design, strings, decryption methods, etc.,&#8221; QuAnXin said. &#8220;So we unified these variants into the CatDDoS-related gangs, even though they may not want to admit it.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Potent Threat, as Always\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">A Potent Threat, as Always<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">DDoS malware and botnets remain a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/300k-internet-hosts-at-risk-for-devastating-loop-dos-attack\" rel=\"noopener\">potent threat for organizations worldwide<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Though many organizations have built substantial redundancies into their network infrastructure to accommodate sudden DDoS-related traffic spikes, threat actors have upped their game as well.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/87-of-ddos-attacks-targeted-windows-os-devices-in-2023\" rel=\"noopener\">recent report from Nexusguard<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> showed threat actors have shifted their attack focus to individual computers and servers. These systems were the primary target in 92% of the DDoS attack attempts that Nexusguard spotted last year \u2014 up sharply from just 68% a year ago. The company attributed the shift in focus to new vulnerabilities in Windows systems and the availability of malware that made it easier for attacks to compromise these systems,<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Significantly, though DDoS attack volumes dropped 55% in 2023, the size of individual attacks grew 233%. In many of these attacks, threat actors continued to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/high-severity-slp-flaw-can-amplify-ddos-attacks-up-to-2-200-times\" rel=\"noopener\">rely on NTP amplification<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 a technique that massively boosts attack traffic. But increasingly, Nexusguard said, they also relied on other techniques such as DNS amplification and HTTPS flooding methods to boost attack traffic volumes.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/catddos-threat-groups-sharply-ramp-up-ddos-attacks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers have spotted a recent surge in activity involving a<\/p>\n","protected":false},"author":12,"featured_media":3777,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3776","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?fit=1000%2C352&ssl=1",1000,352,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?fit=300%2C106&ssl=1",300,106,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?fit=640%2C225&ssl=1",640,225,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?fit=640%2C225&ssl=1",640,225,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?fit=1000%2C352&ssl=1",1000,352,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?fit=1000%2C352&ssl=1",1000,352,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?fit=1000%2C352&ssl=1",1000,352,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?resize=825%2C352&ssl=1",825,352,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?resize=590%2C352&ssl=1",590,352,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/catddos-threat-groups-sharply-ramp-up-ddos-attacks.jpg?fit=1000%2C352&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3776","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3776"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3776\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3777"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3776"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3776"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3776"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}