• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

New Chaos Malware Targets Linux and Windows for Crypto Mining & DDoS Attacks

29 September 2022
in Mining
Reading Time: 5 mins read
A A
0
New Chaos Malware Targets Linux and Windows for Crypto Mining & DDoS Attacks
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
Cryptohopper
ADVERTISEMENT

Black Lotus Labs, the threat intelligence team of Lumen Technologies, has discovered a new multi-function malware making rounds on the cybersphere. Dubbed Chaos, the malware is designed to carry out several types of cyberattacks against Windows and Linux systems.

The earliest certificate researchers discovered was dated April 16, 2022, the same time the first cluster activity was registered. At the time, IP addresses with self-signed certificates containing the word Chaos were at 15, which doubled in May to 39.

As of September 2022, the number of Chaos nodes has climbed to 111, surpassing 93 in August. Mark Dehus, director of threat intelligence for Lumen Black Lotus Labs, said, “We are seeing a complex malware that has quadrupled in size in just two months, and it is well-positioned to continue accelerating.”

“Chaos poses a threat to a variety of consumer and enterprise devices and hosts,” Dehus added. 

Devices at risk from Chaos malware include small office/home office (SOHO) routers, enterprise servers, devices with FreeBSD OS, Windows, and Linux, running on architectures such as ARM (v5 through v8), Intel (x86, x86-64), AMD64, MIPS and MIPS64, AArch64 and PowerPC.

Using the malware, its operators, possibly Chinese, have targeted organizations in gaming, financial services, technology, media and entertainment industries, and cryptocurrency exchanges through DDoS attacks. Threat actors behind Chaos even successfully compromised a GitLab server and targeted fellow cybercriminals involved in DDoS-as-a-service operations.

Black Lotus Labs researchers Danny Adamitis, Steve Rudd and Stephanie Walkenshaw analyzed almost 100 Chaos malware samples and summarized: “Given the suitability of the Chaos malware to operate across a range of consumer and enterprise devices, its multipurpose functionality and the stealth profile of the network infrastructure behind it, we assess with moderate confidence this activity is the work of a cybercriminal actor that is cultivating a network of infected devices to leverage for initial access, DDoS attacks and crypto mining.”

The researchers describe Chaos as the “next iteration of the Kaiji,” a botnet discovered in 2020 that leverages SSH brute forcing to infect new bots to instigate DDoS attacks. Chaos goes beyond Kaiji and metastasizes through SSH key harvesting and automatic vulnerability exploitation to target multiple new architectures, not to mention Windows (in addition to Linux).

“With a significant evolution from its predecessor, Chaos is achieving rapid growth since the first documented evidence of it in the wild,” the researchers noted.

Chaos is written in Go, a language that offers agility, flexibility, difficulty to reverse-engineer, and cross-platform code compilation capabilities (something that many applications lack even today). Denonia, a recent crypto mining malware designed to target AWS Lambda, is also written in Go, though it does not execute on multiple platforms.

See More: New Ducktail Malware Can Bypass Facebook Account Safeguards

However, unlike Denonia, which is purely used for illicit crypto mining by hijacking AWS Lambda resources, Chaos has much broader applicability for cybercriminal activities.

The Chaos attack chain includes the initial setup of the malware on a target machine, establishing persistence, executing staging commands, any additional execution commands, installing a reverse shell, and finally, DDoS or crypto mining operations.

Chaos Attack Infection Chain | Source: Black Lotus Labs (Lumen Technologies)

A differentiating characteristic of Chaos over other malware strains is that it can carry out automated vulnerability exploitation for lateral movement or SSH via brute-forcing with stolen SSH keys. Additionally, the reverse shell enables the malware operator to upload, download or modify files from the command and control (C2) infrastructure located in China.

A few known vulnerabilities that Chaos had listed for exploitation were CVE-2017-17215 and CVE-2022-30525, both of which are remote code execution flaws and reside in personal firewalls by Huawei and Zyxel, respectively. The malware also exploits CVE-2022-1388, a vulnerability in F5’s BIG-IP devices that allows threat actors to execute code arbitrarily to create, delete files, or disable services.

Technical details of the malware are available in a Lumen blog post.

Chaos bots are most prevalent in Europe, according to Black Lotus Labs telemetry data, though the malware was also discovered in some countries in the Americas and Asia-Pacific. Lumen found traffic was absent in Australia, New Zealand, and Africa.

Global Distribution of Chaos Malware

Global Distribution of Chaos Malware | Source: Lumen Technologies

Considering Chaos targets devices that aren’t routinely monitored, consistent monitoring should go a long way in thwarting attacks. More importantly, Black Lotus Labs researchers advised performing appropriate and periodic patch management procedures since it scans for vulnerabilities to spread its infection.

Additionally, admins/users need to change the default passwords with which SOHO routers are shipped and disable remote root access where it is not necessary. Avoid theft of SSH keys by storing them on devices that need them.

Let us know if you enjoyed reading this news on LinkedIn, Twitter, or Facebook. We would love to hear from you!

MORE ON MALWARE



Source link

[crypto-donation-box]
Tags: AttacksChaoscryptoDDoSLinuxMalwareMiningTargetsWindows
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

SecondLive Has Big Plans for NFT Marketplace, Creation Tools

Next Post

NFT Trade Volume Down 97% EPNS Overshadows CryptoPunks, BAYC

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
NFT Trade Volume Down 97% EPNS Overshadows CryptoPunks, BAYC

NFT Trade Volume Down 97% EPNS Overshadows CryptoPunks, BAYC

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk

Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk

12 September 2025
Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to ,000?

Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to $1,000?

12 September 2025
Solana Surges as TVL Hits B and Market Cap Overtakes BNB – CoinCentral

Solana Surges as TVL Hits $13B and Market Cap Overtakes BNB – CoinCentral

12 September 2025
Most big cryptocurrencies rise as Solana rallies – MarketWatch

Most big cryptocurrencies rise as Solana rallies – MarketWatch

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk
  • Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to $1,000?
  • Solana Surges as TVL Hits $13B and Market Cap Overtakes BNB – CoinCentral
  • Most big cryptocurrencies rise as Solana rallies – MarketWatch
  • WLFI Burn Proposal Targets 50% Price Surge With Buybacks

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,842.00
  • ethereumEthereum (ETH) $ 4,608.01
  • xrpXRP (XRP) $ 3.07
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 240.56
  • bnbBNB (BNB) $ 917.57
  • usd-coinUSDC (USDC) $ 0.999805
  • dogecoinDogecoin (DOGE) $ 0.269993
  • staked-etherLido Staked Ether (STETH) $ 4,601.89
  • tronTRON (TRX) $ 0.350192
  • cardanoCardano (ADA) $ 0.903161
  • wrapped-stethWrapped stETH (WSTETH) $ 5,595.55
  • chainlinkChainlink (LINK) $ 24.79
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,972.43
  • hyperliquidHyperliquid (HYPE) $ 55.94
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,863.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.67
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • stellarStellar (XLM) $ 0.396163
  • wrapped-eethWrapped eETH (WEETH) $ 4,959.29
  • avalanche-2Avalanche (AVAX) $ 28.60
  • bitcoin-cashBitcoin Cash (BCH) $ 595.76
  • wethWETH (WETH) $ 4,615.03
  • hedera-hashgraphHedera (HBAR) $ 0.243150
  • litecoinLitecoin (LTC) $ 117.49
  • leo-tokenLEO Token (LEO) $ 9.59
  • crypto-com-chainCronos (CRO) $ 0.255313
  • the-open-networkToncoin (TON) $ 3.20
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • usdsUSDS (USDS) $ 0.999565
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,922.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • polkadotPolkadot (DOT) $ 4.25
  • whitebitWhiteBIT Coin (WBT) $ 44.15
  • uniswapUniswap (UNI) $ 10.10
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.209276
  • ethenaEthena (ENA) $ 0.766403
  • mantleMantle (MNT) $ 1.61
  • moneroMonero (XMR) $ 277.46
  • aaveAave (AAVE) $ 317.02
  • pepePepe (PEPE) $ 0.000011
  • bitget-tokenBitget Token (BGB) $ 4.93
  • daiDai (DAI) $ 0.999952
  • okbOKB (OKB) $ 196.47
  • memecoreMemeCore (M) $ 2.38
  • jito-staked-solJito Staked SOL (JITOSOL) $ 295.95
  • myx-financeMYX Finance (MYX) $ 18.45
  • ondo-financeOndo (ONDO) $ 1.10