Cross-Platform Java Malware Used In DDoS Attacks

A piece of Java malware has been uncovered with the ability to run on Windows, Mac and Linux. It is designed to help carry out distributed denial of service (DDoS) attacks as part of a botnet.

Such cross-platform malware means the malware authors only have to write code once to cover all bases.

The HEUR:Backdoor.Java.Agent.a malware used a vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier to infect users.

Java botnet strikes

It copied itself into the user’s home directory, setting itself up to run at startup and protecting itself from detection with some smart encryption techniques.

“To make analysing and detecting the malware more difficult, its developers used the Zelix Klassmaster obfuscator. In addition to obfuscating bytecode, Zelix encrypts string constants,” explained Anton Ivanov, Kaspersky Lab Expert, in a blog post.

“Zelix generates a different key for each class, which means that in order to decrypt all the strings in the application, you have to analyze all the classes in order to find the decryption keys.”

The bots can be used together for DDoS attacks over either the HTTP or UDP protocols. It is controlled over the IRC protocol, whilst using the PircBot, a Java framework for writing IRC bots quickly and easily.

Attackers have the option to select the address of the target machine, the port number, the DDoS duration and the number of threads to be used. A unique bot identifier is generated on each user machine so the botnet’s owners have total control over their malicious network.

At least one target of the botnet was a bulk email service, said Ivanov.

What do you know about online security? Try our quiz and find out!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

3 days ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

3 days ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

3 days ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

3 days ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

4 days ago