The Growing Threat of Malware Concealed Behind Cloud Services | FortiGuard Labs

Cloud services are increasingly used to host C2 and distribute malware, enabling botnets to store payloads and maintain persistence. FortiGuard Labs details UNSTABLE, Condi, and Skibidi campaigns leveraging cloud infrastructure and CVEs, along with IOCs and protections to defend cloud environments. #UNSTABLE #Condi #Skibidi #VCRUMS #SYKCrypter #JAWSWebserver #TPLinkArcherAX21 #IvantiConnectSecure #CVE-2016-20016 #CVE-2023-1389

Keypoints

  • Threat actors increasingly use cloud services to store, distribute, and coordinate C2 operations, making defense harder and enabling scalability and resilience for attacks.
  • The UNSTABLE botnet targets JAWS Webserver RCE (CVE-2016-20016) to gain initial access and downloads payloads from cloud-hosted sources.
  • The UNSTABLE botnet includes exploitation, scanning, and DDoS modules, and brute-forces other devices using a hard-coded username/password list.
  • Condi DDoS botnet exploits CVE-2023-1389 to gain device control and communicates with a central C2 server; malicious activity is distributed via cloud-hosted binaries.
  • The Skibidi campaign downloads multi-architecture Linux malware, uses ptrace and prctl to evade detection, and encodes strings with XOR before communicating with its C2 server.
  • Fortinet protections include FortiGuard Antivirus detections, IPS signatures, Web Filtering, and free NSE training; strong cloud security and segmentation are recommended.
  • Indicators of compromise (IP addresses, URLs, and file hashes) illustrate how these campaigns operate and where to monitor for threats.

MITRE Techniques

  • [T1190] Exploit Public-Facing Application – Initial access by exploiting JAWS Webserver RCE vulnerability CVE-2016-20016; “Initial access by the UNSTABLE Botnet targets the JAWS Webserver RCE vulnerability, CVE-2016-20016, and retrieves the downloader script “jaws” from 45[.]128[.]232[.]15.”
  • [T1105] Ingress Tool Transfer – The UNSTABLE botnet “retrieves the downloader script “jaws” from 45[.]128[.]232[.]15.”
  • [T1057] Process Discovery – The malware “executes the command “ps -eo pid,comm –no-headers” through “/bin/bash” to get all process PIDs (Process IDs) and command names running without a header line.”
  • [T1059.004] Unix Shell – The malware “executes the command ‘ps -eo pid,comm –no-headers’ through ‘/bin/bash’” to interact with the system.
  • [T1055] Process Injection – “The malware calls the Linux function ‘ptrace’ to handle the process on the victim host… to fork another process to evade detection.”
  • [T1027] Obfuscated/Compressed Files and Information – “The UNSTABLE Botnet… uses XOR to encode its configuration.”
  • [T1583] Acquire Infrastructure – “cloud services to store, distribute, and establish command and control (C2) servers, such as VCRUMS stored on AWS or SYK Crypter distributed via DriveHQ.”

Indicators of Compromise

  • [C2] 45[.]128[.]232[.]15, 45[.]128[.]232[.]90, 45[.]128[.]232[.]229, 45[.]128[.]232[.]234
  • [URLs] hxxp://45[.]128[.]232[.]15, hxxp://45[.]128[.]232[.]90, hxxp://45[.]128[.]232[.]229, hxxp://209[.]141[.]35[.]56/getters, hxxp://45[.]128[.]232[.]234
  • [Files] d5e81e9575dcdbbaa038a5b9251531d8beccedc93bd7d250a4bb2389c1615cd6, 6226e896850de8c5550b63481b138067582ebf361f7c5448d9d0596062150d89, and 2 more hashes

Read more: https://feeds.fortinet.com/~/900044114/0/fortinet/blog/threat-research~The-Growing-Threat-of-Malware-Concealed-Behind-Cloud-Services