Quick update on the Linux.Ngioweb botnet, now it is going after IoT devices
released on 2020-11-13 @ 10:19:12 PM
On August 16, we noticed that 9 N-day vulnerabilities were used to spread Ngioweb V2 samples, involving x86(32/64), ARM(32/64), MIPS(MIPS32/MIPS-III) As well as PPC, Hitachi SH, IBM S/390 and other CPU architectures, this marks the beginning of Ngioweb's attack on IOT devices.
On November 5, 2020, IntezerLabs twittered about a zip archive called "bins.october", which contains 50 Ngioweb samples targeting various linux OS.
With the low low detected rate on VT, and newly added IoT support, we think it is worthing providing a quick update to reflect the key new features with the new variants, so here are some quick outlines.