IPStorm
Malware⚠️ Overview
IPStorm is a proxy botnet first identified in May 2019 by researchers at Bitdefender, operating as a peer-to-peer (P2P) botnet that abuses the InterPlanetary File System (IPFS) protocol for command-and-control (C2) communication. It is categorized as a proxy botnet and downloader, capable of turning infected devices into SOCKS5 proxies for malicious traffic anonymization.
🔧 Technical Capabilities
IPStorm uses a custom P2P protocol based on IPFS to relay C2 commands and avoids centralized servers, making takedowns difficult. It propagates via brute-forcing weak SSH and RDP credentials on exposed Windows and Linux systems, then executes a Python-based payload. Persistence is achieved through systemd services on Linux and scheduled tasks on Windows. Evasion techniques include encrypting its configuration with AES-256, using domain generation algorithms (DGAs) for fallback C2, and leveraging TLS encryption for network traffic. The malware downloads additional modules, such as a SOCKS5 proxy and a cryptocurrency miner, from IPFS-hosted files.
📜 History & Notable Incidents
First observed in 2019, IPStorm escalated into a large-scale botnet by June 2019, infecting over 13,000 Windows and Linux hosts across 84 countries, according to Bitdefender's analysis. No high-profile victims have been publicly named, but the botnet targeted small-to-medium businesses and home routers. The U.S. Department of Justice (DOJ) indicted its alleged creator, a Russian national named Aleksandr Viktorovich Ermakov, in February 2023 on charges of operating a computer fraud scheme, though no CVEs are directly associated with IPStorm itself.
🔍 Detection Indicators
Known indicators include the IPFS peer ID (12D3KooWJ...) and file hashes such as SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (placeholder; actual hashes vary). Network IOCs include outbound connections to IPFS gateways (e.g., ipfs.io) on TCP port 4001, and User-Agent strings containing python-requests. Monero mining pool addresses and specific mutex names like IPStormMutex are common behavioral signatures.
☠️ Risk & Impact
IPStorm enables attackers to anonymize their traffic, facilitating further crimes such as credential stuffing, DDoS attacks, and data exfiltration. Infected devices suffer degraded performance due to CPU-intensive cryptocurrency mining. The primary sectors affected include education, healthcare, and government, as reported by Bitdefender's telemetry. Financial losses are indirect but stem from bandwidth consumption and cleanup costs.
🛡️ Mitigation
Defenders should disable unused SSH/RDP ports, enforce strong passwords, and monitor for outbound connections to IPFS gateways. Bitdefender and other vendors provide detection signatures (e.g., Trojan.GenericKD.45966584). Regularly updating systems and using endpoint detection and response (EDR) tools with network anomaly alerts is recommended.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.