NoaBot
Malware⚠️ Overview
NoaBot is a Linux-based Mirai variant first documented by Akamai’s Security Intelligence Response Team in February 2023. It functions as a hybrid botnet and cryptominer, targeting IoT devices and Linux servers through SSH brute-force attacks. The operators remain unknown but are believed to be financially motivated.
🔧 Technical Capabilities
NoaBot propagates by scanning the internet for systems with open SSH ports (TCP/22) and performing brute-force authentication using a hardcoded credential list (MITRE ATT&CK T1110.001). Upon successful access, it deploys an ELF binary that executes the XMRig coin miner and a DDoS bot capable of HTTP, UDP, and SYN flood attacks. C2 communication uses a custom TCP protocol, and persistence is achieved via cron jobs and SSH key injection. Evasion techniques include UPX packing, string obfuscation, and termination of competing malware processes, as detailed in the Akamai analysis.
📜 History & Notable Incidents
First observed in January 2023, NoaBot campaigns targeted healthcare, education, and telecommunications sectors globally, exploiting unpatched OpenSSH instances. No specific CVE is tied to its initial compromise, but the malware leverages default credentials. As of late 2023, no law enforcement actions have been publicly reported, yet botnet activity waned after Akamai released comprehensive IOCs.
🔍 Detection Indicators
Akamai’s advisory provides SHA256 hashes (e.g., 0xabc…), C2 IP addresses from 5.253.60.0/24, and a User-Agent string "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36" used during scanning. Behavioral indicators include sustained high CPU usage from cryptomining and repeated SSH login failures from external hosts. Network traffic to port 8080 (custom C2) is also a red flag.
☠️ Risk & Impact
NoaBot degrades system performance by consuming CPU cycles for Monero mining and can disrupt services through DDoS attacks. Affected industries face operational downtime and potential data exposure if the infection is used as a foothold for ransomware. Financial losses stem from both cryptomining electricity costs and remediation efforts.
🛡️ Mitigation
Disable SSH password authentication and use key-based access; apply security patches to Linux distributions; deploy network detection rules (e.g., Snort or YARA) from Akamai’s public repository. Regular monitoring for brute-force attempts and unauthorized cron jobs further reduces risk.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.