Skip to content

Malware

WatchBog

According to Intezer, this is a spreader module used by WatchBog.

WatchBog is a Linux malware family.

Background

Intezer describes this as the spreader module belonging to WatchBog. It is a dynamically linked ELF binary built with Cython that pulls its C&C addresses from Pastebin, with each victim assigned a unique identification key for C&C communication. The module includes a BlueKeep scanner that reports hosts that scan positive back to the C&C server, with the traffic RC4-encrypted inside SSL/TLS. It bundles 5 exploits aimed at Jira, Exim, Solr, Jenkins and Nexus Repository Manager 3.


Source: Malpedia (Fraunhofer FKIE).