Fresh Gafgyt Botnet Strain Exploits Fragile SSH Passwords for GPU-Based Cryptocurrency Mining

Researchers in cybersecurity have uncovered a new strain of the Gafgyt botnet that specifically exploits machines with weak SSH credentials to hijack their GPU power for cryptocurrency mining.

According to Assaf Morag from Aqua Security, this development suggests that the botnet is now focusing on more resilient servers found in cloud environments.

Gafgyt, also known by names such as BASHLITE, Lizkebab, and Torlus, has been in operation since 2014. It is notorious for taking advantage of weak or default passwords to seize control of various devices including routers, cameras, and DVRs. It can also exploit vulnerabilities in devices from brands like Dasan, Huawei, Realtek, SonicWall, and Zyxel. Once compromised, these devices form part of a botnet capable of executing distributed denial-of-service (DDoS) attacks. There are indications that Gafgyt, along with Necro, is managed by a threat group named Keksec, also known as Kek Security or FreakOut.

Gafgyt is continuously evolving, with new variants emerging that use the TOR network to obfuscate their activities and incorporate modules from the Mirai botnet’s leaked code. Notably, the source code for Gafgyt was leaked online in early 2015, which has spurred the creation of new versions.

The latest variant targets SSH servers with weak passwords, deploying payloads designed for cryptocurrency mining via “systemd-net,” while also eliminating any competing malware on the infected systems. It employs a worming component, a Go-based SSH scanner called ld-musl-x86, to scan for poorly secured servers and spread the malware. This includes targeting SSH, Telnet, and credentials associated with game servers and cloud services such as AWS, Azure, and Hadoop.

Morag noted that the current cryptominer used is XMRig, specifically designed for Monero mining. In this instance, the miner is configured with the –opencl and –cuda flags to utilize GPU and Nvidia GPU processing power.

“The shift in focus from DDoS attacks to cryptocurrency mining, combined with the target on cloud environments with high CPU and GPU capabilities, marks a significant change from earlier Gafgyt variants,” Morag explained.

Data from Shodan reveals that over 30 million SSH servers are publicly accessible, underscoring the need for users to secure their systems against brute-force attacks and potential breaches.

More Articles & Posts