Researchers have discovered a new DDoS botnet capable of launching attacks with data volumes reaching several Tbps.
Akamai says the malware itself was named “Hinata” by its creator after a character from the Naruto anime series. The security vendor found evidence of ‘HinataBot’ in his HTTP and SSH honeypots and said it was being actively updated by its authors.
While previous versions used DDoS flooding attacks over multiple protocols, the latest HinataBot iteration uses only HTTP and UDP flooding techniques.
The actors behind HinataBot originally distributed Mirai binaries, and this new Go-based effort has multiple nods to the notorious open-source botnet, Akamai said.
For more information, see Mirai: Prepare Your Enterprise for Attacks.
“HinataBot is the latest in a growing list of new Go-based threats that include botnets such as GoBruteForcer and the recently discovered kmsdbot (by SIRT),” it explains.
“Attackers take advantage of Go to take advantage of its high performance, ease of multithreading, and cross-compilation support for multiple architectures and operating systems, but at the expense of added complexity at compile time and difficulty in reverse engineering. This is thought to be due to the increase in the resulting binary.
The vendor claimed that HTTP packet sizes ranged from 484 to 589 bytes, while UDP packets were noticeably larger at 65,549 bytes.
Akamai created its own command and control (C2) infrastructure to execute the simulated attacks.
“Using a 10-second sample set and the theoretical size of the botnet, we can estimate the size of the attack,” it said.
“If the botnet contains only 1000 nodes, the resulting UDP flood weighs about 336 Gbps per second. Over 3.3 Tbps.A HTTP flood at 1000 nodes generates about 2.7 Gbps and over 2 Mrps.At 10,000 nodes, these numbers jump to 27 Gbps, delivering 20.4 Mrps.”
Botnets grow by finding and exploiting old vulnerabilities and brute-forcing weak passwords, increasing the need for organizations to incorporate cyber hygiene into their security strategies.