Malware
MrBlack
aka AESDDoS · Dofloo
MrBlack, first identified in May 2014 by Russian security firm Dr.
MrBlack, also known as AESDDoS, Dofloo, is a Linux malware family.
Background
First documented in May 2014 by the Russian vendor Dr. Web, MrBlack is a Linux-focused botnet built for launching distributed denial-of-service (DDoS) attacks. Incapsula attributed a large-scale DDoS event against its clients in May 2015 to traffic from tens of thousands of small office/home office (SOHO) routers infected with MrBlack, a botnet reaching across more than 109 countries with heavy concentration in Thailand and Brazil.
The malware hunts for routers still using default credentials that expose remote HTTP and SSH access on port 80 and port 22 respectively. Ubiquiti, a U.S. firm supplying bulk networking gear that ISPs lease to subscribers, is among the most affected brands. After compromising a router and injecting itself, MrBlack reaches out to a remote server and uploads the device's system details, enabling that server to issue commands to mount various DDoS attacks, download and run files, and kill processes.
Source: Malpedia (Fraunhofer FKIE).