{"id":50408,"date":"2023-11-01T10:32:49","date_gmt":"2023-11-01T10:32:49","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/11\/01\/security-researchers-observed-deliberate-takedown-of-notorious-mozi-botnet-techcrunch\/"},"modified":"2023-11-01T10:32:49","modified_gmt":"2023-11-01T10:32:49","slug":"security-researchers-observed-deliberate-takedown-of-notorious-mozi-botnet-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/11\/01\/security-researchers-observed-deliberate-takedown-of-notorious-mozi-botnet-techcrunch\/","title":{"rendered":"Security researchers observed &#8216;deliberate&#8217; takedown of notorious Mozi botnet | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"\">\n<div class=\"article__featured-image-wrapper breakout\">\n\t\t\t\n\t\t<\/div>\n<\/p><\/div>\n<div>\n<p id=\"speakable-summary\">Security researchers say they have observed what they believe is a takedown of the notorious Mozi botnet that infiltrated more than a million Internet of Things devices worldwide.<\/p>\n<p>In research shared with TechCrunch ahead of publication on Tuesday, researchers at cybersecurity company ESET say that they witnessed the \u201csudden demise\u201d of Mozi during an investigation into the botnet.<\/p>\n<p>Mozi is a peer-to-peer <a href=\"https:\/\/techcrunch.com\/tag\/internet-of-things\/\" target=\"_blank\" rel=\"noopener\">Internet of Things<\/a> botnet that exploits weak telnet passwords and known exploits to hijack home routers and digital video recorders. The botnet, first discovered in 2019 by 360 Netlab, uses masses of these hijacked devices to launch <a href=\"https:\/\/techcrunch.com\/2023\/08\/12\/fbi-ddos-for-hire-cyberattackers\/\" target=\"_blank\" rel=\"noopener\">DDoS attacks<\/a>, payload execution, and data exfiltration. Mozi has infected more than 1.5 million devices since 2019, with the majority \u2014 at least 830,000 devices \u2014 originating from China.<\/p>\n<p>Microsoft warned in August 2021 that Mozi had evolved to achieve persistence on network gateways manufactured by Netgear, Huawei, and ZTE by adapting its persistence mechanisms. That same month, 360 Netlab <a href=\"https:\/\/blog.netlab.360.com\/the_death_of_mozi_cn\/\" target=\"_blank\" rel=\"noopener\">announced<\/a> that it had assisted in a Chinese law enforcement operation to arrest the authors of Mozi.<\/p>\n<p>ESET, which launched an investigation into Mozi a month prior to these arrests, said it observed a dramatic drop in Mozi\u2019s activity in August this year.<\/p>\n<p>Ivan Be\u0161ina, a senior malware researcher at ESET, tells TechCrunch that the company was monitoring approximately 1,200 unique devices daily worldwide before this. \u201cWe saw 200,000 unique devices in the first half of this year and 40,000 unique devices in July 2023,\u201d said Be\u0161ina. \u201cAfter the drop, our monitoring tool was only able to probe about 100 unique devices daily.\u201d<\/p>\n<p>This drop was observed first in India, and followed by China \u2014 which combined account for 90% of all infected devices worldwide \u2014 Be\u0161ina tells TechCrunch, adding that Russia is the third-most infected country, followed by Thailand and South Korea.<\/p>\n<p>The slump in activity was caused by an update to Mozi bots \u2014 devices infected by Mozi malware \u2014 that stripped them of their functionality, according to ESET, which said it was able to identify and analyze the kill switch that caused Mozi\u2019s demise. This kill switch stopped and replaced the Mozi malware, disabled some system services, executed certain router and device configuration commands, and disabled access to various ports.<\/p>\n<p>ESET says its analysis of the kill switch, which showed a strong connection between the botnet\u2019s original source code and recently used binaries, indicates a \u201cdeliberate and calculated takedown.\u201d The researchers say that this suggests the takedown was likely carried out by the original Mozi botnet creator or Chinese law enforcement, perhaps enlisting or forcing the cooperation of the botnet operators.<\/p>\n<p>\u201cThe biggest piece of evidence is that this kill switch update was signed with the correct private key. Without this, the infected devices would not accept and apply this update,\u201d Be\u0161ina told TechCrunch. \u201cAs far as we know only the original Mozi operators had access to this private signing key. The only other party that could reasonably acquire this private signing key is the Chinese law enforcement agency that caught the Mozi operators in July 2021.\u201d<\/p>\n<p>Be\u0161ina added that ESET\u2019s analysis of the kill switch updates showed that it must have been compiled from the same base source code. \u201cThe new kill switch update is just a \u2018stripped down\u2019 version of the original Mozi,\u201d said Be\u0161ina.<\/p>\n<p>The apparent takedown of Mozi comes weeks after the FBI <a href=\"https:\/\/techcrunch.com\/2023\/09\/01\/fbi-qakbot-takedown-operation-duck-hunt\/\" target=\"_blank\" rel=\"noopener\">took down and dismantled<\/a> the notorious Qakbot botnet, a banking trojan that became notorious for providing an initial foothold on a victim\u2019s network for other hackers to buy access and deliver their own malware.<\/p>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2023\/11\/01\/mozi-botnet-take-down-china\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers say they have observed what they believe is a takedown of the notorious Mozi botnet that infiltrated more than a million Internet of Things devices worldwide. In research shared with TechCrunch ahead of publication on Tuesday, researchers at cybersecurity company ESET say that they witnessed the \u201csudden demise\u201d of Mozi during an investigation [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":50409,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-50408","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/50408","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=50408"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/50408\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/50409"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=50408"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=50408"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=50408"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}