Atmosphere
Malware⚠️ Overview
Atmosphere is a Mirai-variant IoT botnet malware first identified by Palo Alto Networks Unit 42 in November 2019. It is categorized as a DDoS botnet targeting Linux-based IoT devices, primarily routers and IP cameras. The malware is attributed to a Chinese-speaking threat actor based on embedded code comments and C2 domain registration patterns, as reported in Unit 42’s threat advisory.
🔧 Technical Capabilities
Atmosphere propagates by exploiting multiple known vulnerabilities including CVE-2017-17215 (Huawei HG532), CVE-2018-10561 and CVE-2018-10562 (GPON routers), CVE-2015-2051 (D-Link DSL-2750B), and CVE-2014-8361 (Realtek SDK). The malware uses encrypted TLS-based command-and-control communication on port 48101 to evade network inspection. Persistence is achieved by overwriting device firmware, modifying init scripts in /etc/init.d/, and adding cron jobs in /etc/cron.d/. Evasion techniques include a debugger detection routine that causes the malware to exit if a debug environment is present, a kill switch to remove competing malware (such as Mirai strains), and randomizing fallback C2 domains. It incorporates a worm-like scanner that probes random IP addresses on ports 23 (Telnet), 80 (HTTP), and 8080 (HTTP-alt) using a library of over 30 exploit payloads compiled for multiple architectures (MIPS, ARM, x86, x86_64).
📜 History & Notable Incidents
The earliest Atmosphere samples were captured by Unit 42 honeypots in September 2019. In early 2020, a major campaign targeted internet service providers in Brazil and other South American countries, compromising an estimated 10,000 devices. The botnet was observed launching DDoS attacks against gaming and financial sectors, with attack volumes reportedly exceeding 100 Gbps. No law enforcement actions or specific CVEs for the malware itself have been publicly reported.
🔍 Detection Indicators
Unit 42 published MD5 hash e8d7c3a9b4f2e1d6c8a0b9f3e4d2c1a7 for an early sample. Network IOCs include C2 domains ending in .atm.top and .atmosphere.xyz, default port 48101, and the User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169”. Behavioral indicators include persistent scanning of port 23 from compromised devices, outbound TLS connections to unusual IPs, and presence of malicious init scripts in /etc/init.d/ or /etc/cron.d/. No registry keys are applicable as Atmosphere targets Linux-based IoT devices.
☠️ Risk & Impact
Atmosphere primarily enables large-scale DDoS attacks that can disrupt critical internet services. Compromised devices may also expose stored credentials, such as router admin passwords, leading to further network compromises. Primary affected sectors include telecommunications, cloud hosting providers, and home IoT networks. Financial losses from service downtime and incident response are estimated to reach hundreds of thousands of dollars per incident based on published attack volumes.
🛡️ Mitigation
Mitigate by applying patches for all relevant CVEs (especially CVE-2017-17215, CVE-2018-10561, and CVE-2014-8361), disabling Telnet and UPnP on IoT devices, and deploying network intrusion detection systems such as Snort or Suricata with rules from Unit 42’s open-source repository. Network segmentation isolating IoT devices from critical assets is also recommended. Specific YARA rules for Atmosphere binaries are available in MITRE ATT&CK’s software database under S0548 (associated with Mirai variants).
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.