Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

DreamBus Botnet Exploiting RocketMQ Vulnerability to Delivery Cryptocurrency Miner

The DreamBus botnet has resurfaced and it has been exploiting a recently patched Apache RocketMQ vulnerability to deliver a Monero miner.

The DreamBus botnet has resurfaced after a two-year break and it has been seen exploiting a recently patched Apache RocketMQ vulnerability in attacks whose goal is the delivery of a cryptocurrency miner.

Apache RocketMQ is a widely used distributed messaging and streaming platform. The exploited vulnerability is tracked as CVE-2023-33246 and its existence came to light in late May, when RocketMQ version 5.1.1 was released to patch the issue. 

CVE-2023-33246 has been classified as ‘critical’ and it can be exploited by an unauthenticated attacker for remote command execution.

Details and proof-of-concept (PoC) exploits emerged in June, and reports of exploitation in the wild emerged shortly after. The ZoomEye cyberspace mapping service had recorded more than 6,000 traces of intrusion at the time — mainly in China — and the number has now gone up to 11,000. 

Juniper Networks reported this week that it started seeing attacks exploiting CVE-2023-33246 in early June, with a peak reached in mid-June, as part of activity associated with the DreamBus botnet. 

The first exploitation attempts were designed to look for vulnerable RocketMQ servers, but threat actors later started delivering a malicious bash script designed to download the main module of the DreamBus malware.

Advertisement. Scroll to continue reading.

This main module, which is an ELF Linux binary, has been packed with the UPX executable file compressor but in a way that makes the malware’s analysis more difficult.

DreamBus is a Linux malware that emerged in early 2019, but Juniper said it had not been seen since 2021, until now. 

The main goal in this case appears to be the distribution of a Monero cryptocurrency miner on infected systems. However, Juniper researchers said DreamBus can also attempt to spread to internal and external IP ranges. This worm-like behavior is not new for the malware. 

“As DreamBus malicious threat actors resurface, their primary objective remains the installation of a Monero cryptocurrency miner. However, the presence of a modular bot like the DreamBus malware equipped with the ability to execute bash scripts provides these cybercriminals the potential to diversify their attack repertoire, including the installation of various other forms of malware,” Juniper said.

Juniper provides indicators of compromise (IoCs) and recommendations for protecting systems against such attacks. 

Related: Qakbot Botnet Disrupted in Operation ‘Duck Hunt’

Related: Multiple DDoS Botnets Exploiting Recent Zyxel Vulnerability

Related: New ‘GoBruteforcer’ Botnet Targets Web Servers

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.