Satori botnet successor targets Ethereum mining rigs
Satori botnet successor targets Ethereum mining rigs.
The Satori botnet has raised its head once again with an unusual target -- rigs which mine the cryptocurrency Ethereum (ETH).
Satori, a botnet which exploits a Huawei vulnerability and bug in Realtek SDK-based devices to enslave PCs, was originally based on the notorious Mirai IoT botnet.
While Mirai secured millions of IoT devices by exploiting the use of default credentials, Satori was able to amass hundreds of thousands of devices purely through these two exploits.
Security teams rapidly responded to the threat and sinkholed the C&C server in December last year, but it is possible this new variant is the creation of the same threat actor, due to similarities in code and scanning capabilities.