October 9, 2020 By David Bisson 2 min read

A new peer-to-peer (P2P) botnet called FritzFrog has breached over 500 secure shell (SSH) servers, including those operated by a railway company and some well-known educational institutions in the U.S. and Europe.

FritzFrog was first discovered in January by Guardicore Labs. The security firm observed the botnet execute its malicious processes ‘ifconfig’ and ‘nginx.’ Researchers responded by launching an investigation into the threat.

In the process, they found that FritzFrog lacked any centralized command-and-control (C&C) infrastructure. The company subsequently developed a Golang-based client program they dubbed ‘frogger’ for the purpose of creating their own nodes and joining the P2P network. They observed a total of over 13,000 botnet attacks and 20 different binaries of the botnet malware within the FritzFrog’s network.

But, what does this actually mean?

How is FritzFrog Different From Other Botnets? 

The dissection of the botnet revealed several properties that set FritzFrog apart from other P2P botnets. Most notably, FritzFrog is fileless; it didn’t arrive with any working directory. Instead, it used binary large objects (BLOBs), which are binary data collections that load in memory as a single entity, to transfer and assemble its files. The threat included a map to track each BLOB along with its hash value. This enabled the malware to make the transfer of files stored on those BLOBs between different nodes.

It also used aggressive brute-force attacks based on an extensive dictionary against targets distributed evenly among nodes. Once it successfully compromised those machines, the threat proceeded to keep its databases of targets and breached machines up to date — all while using a P2P protocol that was completely proprietary.

Other Major P2P Botnets in 2020

These qualities set FritzFrog apart from other recent P2P botnets. In early April, Netlab 360 published its research on DDG, a botnet that first attracted the security firm’s attention in January 2018 for its efforts to mine for Monero. A new version emerged in January 2019. This variant arrived with a Memberlist-based P2P mechanism, making it one of the world’s first P2P-based cryptomining botnets.

A few days later in April, Mozi emerged. At the time of analysis, this malware consisted of the source code borrowed from the Gafgyt, Mirai and IoT Reaper botnets. Mozi differentiated itself from these threats by rejecting centralized C&C infrastructure and opting for a P2P network. It used this architecture to mainly target home routers and DVRs in order to launch distributed denial-of-service (DDoS) attacks, exfiltrate data and execute payloads.

How to Defend Against P2P Botnets

Botnets with P2P networks are difficult to shut down. In the absence of centralized C&C infrastructure, infected bots can continue to relay instructions to one another even if large swaths of the botnet go down.

Acknowledging this reality, organizations should take it upon themselves to defend their Internet of things (IoT) devices against botnet malware like FritzFrog. They can do so first by investing in an incident response team responsible for investigating potential compromises. This team can also oversee the vulnerability management process on the organization’s smart products. Simultaneously, the organization should commit itself to upholding IoT security best practices by having its security teams regularly review the configurations of its IoT devices and change the admin passwords for each device.

More from

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today