<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mozi &#8211; The Integrator</title>
	<atom:link href="https://integratormedia.com/tag/mozi/feed/" rel="self" type="application/rss+xml" />
	<link>https://integratormedia.com</link>
	<description>EMEA&#8217;s Most Sought-After Publication by SMEs and Global Corporates</description>
	<lastBuildDate>Tue, 23 Nov 2021 13:09:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.5</generator>
	<item>
		<title>Global Lockdowns May Limit COVID-19, But Not DDoS</title>
		<link>https://integratormedia.com/2021/11/23/global-lockdowns-may-limit-covid-19-but-not-ddos/</link>
					<comments>https://integratormedia.com/2021/11/23/global-lockdowns-may-limit-covid-19-but-not-ddos/?noamp=mobile#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 23 Nov 2021 13:09:13 +0000</pubDate>
				<category><![CDATA[Features]]></category>
		<category><![CDATA[Tech Features]]></category>
		<category><![CDATA[A10 Networks]]></category>
		<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Mozi]]></category>
		<category><![CDATA[Portmap]]></category>
		<category><![CDATA[SARS-CoV-2]]></category>
		<category><![CDATA[SNMP]]></category>
		<category><![CDATA[TFTP]]></category>
		<guid isPermaLink="false">https://varonline.com/?p=11500</guid>

					<description><![CDATA[By: Amr Alashaal, A10 Networks The world has been going through significant changes: facing a global COVID-19 pandemic, researching how the SARS-CoV-2 virus works, and then delivering a defense via vaccines to fight back. Similarly, in the world of cybersecurity, we saw many changes in the first half of 2021. A10 Networks’ recent report on [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><strong><em>By: Amr Alashaal, A10 Networks</em></strong></p>
<p>The world has been going through significant changes: facing a global COVID-19 pandemic, researching how the SARS-CoV-2 virus works, and then delivering a defense via vaccines to fight back. Similarly, in the world of cybersecurity, we saw many changes in the first half of 2021. A10 Networks’ recent report on the H1 2021: The Global State of DDoS Weapons sheds light on potential DDoS weapons and their behavior to ensure DDoS attacks can be mitigated regardless of the country or organization they belong to. The report provides detailed insights into the origins of DDoS activity, how easily and quickly modern malware can hijack IoT devices and convert them into malicious botnets, and what organizations can do to protect against such activities.</p>
<div id="attachment_11029" style="width: 219px" class="wp-caption alignright"><a href="https://varonline.com/wp-content/uploads/2021/10/Amr-Alashaal-Regional-Vice-President-Middle-East-at-A10-Networks-e1635400385141.jpg"><img decoding="async" aria-describedby="caption-attachment-11029" class=" wp-image-11029" src="https://varonline.com/wp-content/uploads/2021/10/Amr-Alashaal-Regional-Vice-President-Middle-East-at-A10-Networks-e1635400385141-275x300.jpg" alt="" width="209" height="228" /></a><p id="caption-attachment-11029" class="wp-caption-text"><em>Amr Alashaal, Regional Vice President &#8211; Middle East at A10 Networks</em></p></div>
<p>As per the report, while DDoS attacks kept growing in size and frequency, attackers particularly focused on low-volume attacks that ran for longer periods, frequently injecting attack traffic. These low-volume attacks helped them evade basic defensive measures, but low thresholds still had a significant impact on systems and operations. We also saw some positive changes, for example, a large-scale botnet takedown by an international operation across different continents. Organizations began paying a lot more attention to DDoS, raising awareness around the role of malware in DDoS attacks, and providing insights into how systems and operations can be protected from attacks, large or small.</p>
<p>Organizations are paying more attention to infectious malware, like Mozi. Some vigilante groups have even started using DDoS attacks as a defensive measure, attacking systems that exhibit scanning behavior. A10 has seen this behavior exhibited on our honeypots. While employing DDoS attacks against the very attackers might be considered controversial, it helps ultimately reduce DDoS attacks and the expansion of botnets.</p>
<p><strong>Key Insights from the report:</strong></p>
<ul>
<li>The total number of DDoS weapons has increased by approximately 2.5 million in the first half of 2021, in line with the last two reports, with a total number of approximately 15 million weapons. This number includes both reflected amplification weapons as well as botnet agents readily available for exploitation by attackers.</li>
<li>SSDP (Simple Service Discovery Protocol), which can be a dangerous and potent DDoS weapon, remained at the top with over 3.2 million potential weapons exposed to the internet. The rest of the weapons remained virtually the same as before, with SNMP, Portmap, TFTP, and DNS Resolvers as the top five. It is important to note that almost all of these weapons experienced a growth in numbers except for DNS Resolvers, which had a reduction of over 300,000 weapons.</li>
<li>China continues to lead in hosting the highest number of potential DDoS weapons (almost 2 million), including both amplification weapons and botnet agents.</li>
<li>The United States remains the second-largest source of DDoS weaponry, particularly amplification weapons.</li>
<li>The number of total botnet agents was almost halved, with China hosting 44% of the total number of drones available worldwide.</li>
<li>Mozi, one of the highly prevalent malware in the DDoS world, topped out at over 360,000 unique systems using more than 285,000 unique source IP addresses, likely due to address translation. First identified in 2019, Mozi has been evolving and increasing in size ever since. It can now persist on network devices by infiltrating the device’s file system, remaining functional even after the device has been rebooted. The Mozi botnet includes infected bots around the globe with China, India, Russia, Brazil, and Vietnam leading the list of countries and regions.</li>
</ul>
<p>In conclusion, cybercriminals and cyberattacks have been evolving at a steady pace. With new attacks and new malware variants that come out, we see new layers of sophistication in how IoT and smart devices are weaponized. While these attacks become more prevalent, one thing is quite obvious — they don’t go unnoticed. Now is the time to update our defensive strategies by incorporating the Zero Trust model and investing in modern, artificial intelligence/machine learning-based solutions that will not only defeat attacks in real-time but also protect against the unknown.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://integratormedia.com/2021/11/23/global-lockdowns-may-limit-covid-19-but-not-ddos/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Tips to Protect Enterprise Networks and Resources Against Mozi</title>
		<link>https://integratormedia.com/2021/10/25/tips-to-protect-enterprise-networks-and-resources-against-mozi/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 25 Oct 2021 12:32:02 +0000</pubDate>
				<category><![CDATA[Features]]></category>
		<category><![CDATA[Tech Features]]></category>
		<category><![CDATA[AI/ML Techniques]]></category>
		<category><![CDATA[Block BitTorrent]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Mozi]]></category>
		<category><![CDATA[RCEs]]></category>
		<category><![CDATA[Zero Trust model]]></category>
		<guid isPermaLink="false">https://varonline.com/?p=11396</guid>

					<description><![CDATA[Malware has been playing an important role in the expansion of botnets, automating the process of bot infection and recruitment. These botnets are then used to launch large-scale DDoS attacks. One highly prevalent malware in the DDoS world is Mozi. Mozi is a DDoS-focused botnet that utilizes a large set of Remote Code Executions (RCEs) [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Malware has been playing an important role in the expansion of botnets, automating the process of bot infection and recruitment. These botnets are then used to launch large-scale DDoS attacks. One highly prevalent malware in the DDoS world is Mozi.</p>
<p>Mozi is a DDoS-focused botnet that utilizes a large set of Remote Code Executions (RCEs) to leverage CVEs in IoT devices for infection. These IoT devices include readily available and commonly used DVRs and network gateways. Once infected, the botnet uses peer-to-peer connectivity to send and receive configuration updates and attack commands. Mozi was first identified in 2019 and has been evolving and increasing in size ever since. It can now persist on network devices by infiltrating the device’s file system, remaining functional even after the device has been rebooted. During the first half of 2021, Mozi topped out at over 360,000 unique systems using more than 285,000 unique source IP addresses, likely due to address translation.</p>
<div id="attachment_11029" style="width: 203px" class="wp-caption alignright"><a href="https://varonline.com/wp-content/uploads/2021/10/Amr-Alashaal-Regional-Vice-President-Middle-East-at-A10-Networks-e1635400385141.jpg"><img decoding="async" aria-describedby="caption-attachment-11029" class=" wp-image-11029" src="https://varonline.com/wp-content/uploads/2021/10/Amr-Alashaal-Regional-Vice-President-Middle-East-at-A10-Networks-e1635400385141-275x300.jpg" alt="" width="193" height="211" /></a><p id="caption-attachment-11029" class="wp-caption-text"><em>Amr Alashaal, Regional Vice President &#8211; Middle East at A10 Networks</em></p></div>
<p>In order to protect their networks and resources, organizations need to take the following steps to block systems infected by Mozi and the malicious traffic generated by them:</p>
<p><strong>Never Trust, Always Verify:</strong> Incorporate the Zero Trust model and its key principles into your security strategy. Create micro-perimeters within your networks. Limit access to your resources and invest in modern, AI/ML-based solutions. Ensure visibility into not only the endpoints and network nodes, but also into users, their activities, and workflows.</p>
<p><strong>Investigate Whether You are Already Infected:</strong> The initial infection of Mozi comes in the form of RCEs sent using ports 80, 8080, 8443, etc. This can make initial infections stand out, which can help in tracking them with low false positives. If your network devices suddenly start generating abnormal amounts of TCP or UDP traffic, immediately isolate suspicious devices and limit the traffic originating from them. If this is not possible, then apply global rate limiting on all traffic until you track the source.</p>
<p><strong>Observe and Block Commonly Exploited Ports:</strong> Incorporate the Zero Trust Closely monitor any traffic using TCP ports 60001, 37215, 5555, 52869, 49152, both before or after a suspected infection. While these aren’t the only ports Mozi uses, they may help find the needle in the haystack. As a general good practice, monitor and block sources that send TCP SYNs to ports 23 and 2323 as most malware use Telnet to initiate IoT device infections.</p>
<p><strong>Take a Closer Look at the Payloads:</strong> If your network devices are generating large amounts of traffic, look at the payloads (i.e., the HTTP POST as shown on page 13). RegEx can be used to filter these malicious traffic requests out and block them before they infect other devices.</p>
<p><strong>Block BitTorrent:</strong> Since BitTorrent is one of the most common peer-to-peer networks used by Mozi for Command and Control (C2) communications, any BitTorrent traffic coming into or going out of the network should be blocked. The sheer amount of BitTorrent traffic could be a dead giveaway of infection depending on your customer type.</p>
<p><strong>Ensure Your Security is up to Date:</strong> Make sure your security infrastructure is updated regularly and that your IoT devices are running the latest version of firmware with all the necessary security patches applied. Keep track of CVEs for your network devices and seek out help if there are any patches available. If fixes are not readily available, take appropriate action based on the particular CVEs.</p>
<p><strong>Employ or Review DDoS Baselining and AI/ML Techniques:</strong> Using modern DDoS techniques like baselining to see anomalous behavior versus historical norms, and AI/ML techniques, for detection and zero-day attack prevention, can be a force multiplier for your security team as manual tasks can be discovered and dealt with efficiently and 24&#215;7.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
