• Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service
Friday, May 1, 2026
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
Ledger - Crypto Beginners Pack
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
No Result
View All Result

New ‘NKAbuse’ Linux Malware Uses Blockchain Technology to Spread

December 16, 2023
in Blockchain
0

Cybersecurity researchers from Kaspersky’s Global Emergency Response Team (GERT) have identified that the NKAbuse malware is actively targeting devices in Colombia, Mexico, and Vietnam.

Kaspersky’s Global Emergency Response Team (GERT) has discovered a new multiplatform malware threat that uses innovative tactics to hijack victims. The malware, dubbed NKAbuse, uses New Kind of Network (NKN) technology, a blockchain-powered peer-to-peer network protocol to spread its infection.

NKAbuse is a Go-based backdoor used as a botnet to target Linux desktops and potentially IoT devices. The malware allows attackers to launch Distributed Denial of Service (DDoS) attacks or fling remote access trojans (RATs).

It is worth noting that the backdoor relies on NKN for anonymous yet reliable data exchange. For your information, NKN is an open-source protocol that allows peer-to-peer data exchange over a public blockchain with over 60,000 active nodes. It aims to provide a decentralized alternative to client-to-server methods while preserving speed and privacy.

The botnet can carry out flooding attacks using the 60,000 official nodes and links back to its C2 (command & control) servers. It features an extensive arsenal of DDoS attacks and multiple features to turn into a powerful backdoor or RAT.

The malware implant creates a structure called “Heartbeat” that communicates with the bot master regularly. It stores information about the infected host, including the victim’s PID, IP address, free memory, and current configuration.

Kaspersky researchers uncovered NKAbuse while investigating an incident targeting one of its customers in the finance sector. Further examination revealed that NKAbuse exploits an old Apache Struts 2 vulnerability (tracked as CVE-2017-5638).

The vulnerability, as reported by Hackread.com in December 2017, allows attackers to execute commands on the server using a “shell” header and Bash and then execute a command to download the initial script.

NKAbuse leverages the NKN protocol to communicate with the bot master and send/receive information. It creates a new account and multiclient to simultaneously send/receive data from multiple clients.

The NKN account is initialized with a 64-character string representing the public key and remote address. Once the client is set up, the malware establishes a handler to accept incoming messages, which contains 42 cases, each performing different actions based on the sent code.

NKN data routing diagram (Image: Kaspersky’s GERT)

Researchers observed that attackers exploited the Struts 2 flaw using a publicly available proof of concept exploit. They executed a remote shell script, determining the victim’s operating system and installing a second-stage payload. Using NKAbuse’s amd64 version, the attack achieved persistence through cron jobs.

“This particular implant appears to have been meticulously crafted for integration into a botnet, yet it can adapt to functioning as a backdoor in a specific host and its use of blockchain technology ensures both reliability and anonymity, which indicates the potential for this botnet to expand steadily over time, seemingly devoid of an identifiable central controller.”

Kaspersky’s Global Emergency Response Team (GERT)

NKAbuse has no self-propagation functionality and can target at least eight different architectures, although Linux is the priority. Successful implantation can lead to data compromise, theft, remote administration, persistence, and DDoS attacks.

For now, its operators are focusing on infecting devices in Colombia, Mexico, and Vietnam. However, researchers suspect its potential for expansion over time.

RELATED ARTICLES

  1. Free Download Manager Site Pushed Linux Password Stealer
  2. New XorDdos-Linked Linux RAT Krasue Targeting Telecom Firms
  3. Hamas Hackers Targeting Israelis with New BiBi-Linux Wiper Malware
  4. Kinsing Crypto Malware Hits Linux Systems via Apache ActiveMQ Flaw
  5. Looney Tunables Linux Vulnerability Exposes Millions of Systems to Attack



This news is republished from another source.


Previous Post

What’s The Metaverse? Meaning, Best Projects And Crypto

Next Post

Bitcoin Dumps Below $42K, What Next for BTC? Experts Advise To Buy This DeFi Token Instead

Next Post

Bitcoin Dumps Below $42K, What Next for BTC? Experts Advise To Buy This DeFi Token Instead

Name Price
Kinza Babylon Staked BTC
Kinza Babylon Staked BTC (KBTC)
$83,270.00
Steakhouse EURCV Morpho Vault
Steakhouse EURCV Morpho Vault (STEAKEURCV)
$0.000000
Eureka Bridged PAX Gold (Terra)
Eureka Bridged PAX Gold (Terra) (PAXG)
$4,182.54
Vested XOR
Vested XOR (VXOR)
$3,404.23
ICPanda DAO
ICPanda DAO (PANDA)
$0.003106
TruFin Staked APT
TruFin Staked APT (TRUAPT)
$8.02
kpk ETH Prime
kpk ETH Prime (KPK ETH PRIME)
$2,036.25
ApeSwap
ApeSwap (BANANA)
$0.000000
bitcoin
Bitcoin (BTC)
$78,425.00
ethereum
Ethereum (ETH)
$2,306.85

Dogecoin

Will Dogecoin Recover or Dive Below $0.1? 5thScape Set to Dominate 2024! %

July 15, 2024

Investors Shift to Clandeno (CLD) ICO Amid Global Market Uncertainty as Dogecoin (DOGE) and Polkadot (DOT) Drop

July 14, 2024

Dogecoin (DOGE) and Solana (SOL) Lead Crypto Market Recovery as Bitcoin (BTC) Reclaims $60K

July 14, 2024

DOGECOIN PRICE ANALYSIS & PREDICTION (July 13) – Doge Trades Calmly At $0.1, Can It Gain Strength From This Key Level? 

July 14, 2024

Analyst Who Bought Solana At $0.11 And Sold For $250 Says Buy ETFSwap (ETFS) At $0.01831 Now Instead Of Dogecoin (DOGE)

July 13, 2024

Leap Ahead with MOONHOP Presale As 4900% Growth Projection Dwarfs Notcoin & Dogecoin’s Declines

July 13, 2024

Metaverse

Ciz Verse Announces the Launch of Its Bitcoin-Powered Metaverse

July 15, 2024

Mil.k partners AirAsia rewards and The Sandbox to engage consumers in the metaverse

July 15, 2024

Lado Okhotnikov Reveals The Secrets Of The Realistic Meta Force Metaverse

July 14, 2024

GensoKishi Metaverse (MV) Price Down 18.4% This Week

July 14, 2024

The 3 Smartest Metaverse Stocks to Buy With $500 Right Now

July 14, 2024

Top 3 Metaverse Tokens For 3X Surge This Bull Rally!

July 13, 2024

transcosmos launches Roblox metaverse services with EbuAction

July 13, 2024
No Result
View All Result

Pages

  • Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service

Tether

Zimbabwe ZiG Hits Record Low as Interest in Tether (USDT) Rises

July 15, 2024

Solana

How Solana flipped Ethereum, Bitcoin in NFT Adoption

July 15, 2024

Solana Reaches Market Capitalization of $67.27 Billion (SOL)

July 14, 2024

Advertisement

  • Shop
  • Privacy Policy
  • Terms of Service

© 2023 XXL24


No Result
View All Result
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop

© 2023 XXL24


  • Kinza Babylon Staked BTCKinza Babylon Staked BTC(KBTC)$83,270.000.00%
  • Steakhouse EURCV Morpho VaultSteakhouse EURCV Morpho Vault(STEAKEURCV)$0.000000-100.00%
  • Eureka Bridged PAX Gold (Terra)Eureka Bridged PAX Gold (Terra)(PAXG)$4,182.540.23%
  • Vested XORVested XOR(VXOR)$3,404.231,000.00%
  • ICPanda DAOICPanda DAO(PANDA)$0.003106-39.39%
  • TruFin Staked APTTruFin Staked APT(TRUAPT)$8.020.00%
  • kpk ETH Primekpk ETH Prime(KPK ETH PRIME)$2,036.250.01%
  • ApeSwapApeSwap(BANANA)$0.0000000.00%
  • bitcoinBitcoin(BTC)$78,425.002.62%
  • ethereumEthereum(ETH)$2,306.851.88%
  • kpk ETH Yieldkpk ETH Yield(KPK ETH YIELD)$2,031.88-0.04%
  • tetherTether(USDT)$1.000.03%
  • rippleXRP(XRP)$1.391.97%
  • JPool Staked SOLJPool Staked SOL(JSOL)$170.103.95%
  • binancecoinBNB(BNB)$620.610.61%
  • usd-coinUSDC(USDC)$1.000.02%
  • solanaSolana(SOL)$84.301.21%
  • tronTRON(TRX)$0.3258580.04%
  • staked-etherLido Staked Ether(STETH)$2,262.76-3.72%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.06%
  • dogecoinDogecoin(DOGE)$0.1092192.12%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$58.612.34%
  • Gaj FinanceGaj Finance(GAJ)$0.0059271.46%
  • Content BitcoinContent Bitcoin(CTB)$24.482.55%
  • USD OneUSD One(USD1)$1.000.11%
  • USDSUSDS(USDS)$1.000.00%
  • Wrapped stETHWrapped stETH(WSTETH)$2,773.89-3.48%
  • UGOLD Inc.UGOLD Inc.(UGOLD)$3,042.460.08%
  • HyperliquidHyperliquid(HYPE)$40.914.19%
  • leo-tokenLEO Token(LEO)$10.340.20%
  • ParkcoinParkcoin(KPK)$1.101.76%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$76,102.00-3.36%
  • cardanoCardano(ADA)$0.2499481.08%
  • bitcoin-cashBitcoin Cash(BCH)$452.732.23%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.07%
  • Wrapped Beacon ETHWrapped Beacon ETH(WBETH)$2,462.35-3.82%
  • Wrapped eETHWrapped eETH(WEETH)$2,462.97-3.62%
  • moneroMonero(XMR)$375.90-1.12%
  • Yay StakeStone EtherYay StakeStone Ether(YAYSTONE)$2,671.07-2.84%
  • chainlinkChainlink(LINK)$9.220.94%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$76,319.00-3.28%
  • zcashZcash(ZEC)$362.177.70%
  • PengPeng(PENG)$0.60-13.59%
  • CantonCanton(CC)$0.149442-1.42%
  • stellarStellar(XLM)$0.1618121.54%
  • wethWETH(WETH)$2,264.05-3.78%
  • MurasakiMurasaki(MURA)$4.32-12.46%
  • USD1USD1(USD1)$1.000.02%
  • sUSDSsUSDS(SUSDS)$1.090.12%
  • USDT0USDT0(USDT0)$1.00-0.11%