Skip to content
CyberWire Daily

Another infection with new malware. [Research Saturday]

Nov 19, 2022 · 19 min · Season 5 · Episode 259Bonus
0:00-19:25

Streams straight from the publisher. podnod never proxies or re-hosts episode audio.

Larry Cashdollar, Principal Security Intelligence Response Engineer from Akamai Technologies, joins Dave to talk about their research on "KmsdBot: The Attack and Mine Malware." Akamai's Security Research team has found a new malware that infected their honeypot, which they have dubbed KmsdBot. 

The research states "The malware attacks using UDP, TCP, HTTP POST, and GET, along with a command and control infrastructure (C2), which communicates over TCP." The botnet targets weak login credentials and then infects systems via an SSH connection.

The research can be found here: