New FritzFrog P2P Botnet Targets Multiple Sectors to Mine Monero

NJCCIC Alert

Original Release Date: 8/20/2020

Summary

Guardicore researchers discovered a new sophisticated peer-to-peer (P2P) botnet dubbed FritzFrog. The malware attempts to brute force and propagate via SSH servers, and is actively targeting education, government, finance, telecommunications, and healthcare sectors with a primary goal of deploying XMRig to mine for the Monero cryptocurrency. FritzFrog successfully breached more than 500 SSH servers since January 2020. The malware first attempts to connect to a target server over SSH ports 22 or 2222 and then immediately erases itself after successful installation. The malicious processes are run as ifconfig and nginx to evade detection and launch a netcat client on port 1234 to listen for additional commands. A separate malware process named libexec runs to begin cryptocurrency mining over port 5555. Additionally, FritzFrog enables a backdoor by adding a single public SSH-RSA key to the authorized keyfile, granting the threat actor access regardless of whether passwords are changed. Researchers have identified 20 different versions of the malware.

Recommendations

The NJCCIC recommends administrators use strong, unique passwords and consider using a public key authentication method. Additionally, consider enabling process-based segmentation rules as well as changing SSH ports, or disabling access to those ports not in use. Guardicore provides a FritzFrog detection script to detect indicators of compromise. Further technical information and IOCs can be found in the Guardicore article.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.