• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new python based fbot hacking toolkit aims at cloud and saas

New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms

You are here: Home / General Cyber Security News / New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms
January 11, 2024

A new Python-primarily based hacking device known as FBot has been uncovered concentrating on web servers, cloud services, material management devices (CMS), and SaaS platforms this sort of as Amazon Web Services (AWS), Microsoft 365, PayPal, Sendgrid, and Twilio.

“Important options include credential harvesting for spamming attacks, AWS account hijacking applications, and features to allow attacks against PayPal and different SaaS accounts,” SentinelOne security researcher Alex Delamotte explained in a report shared with The Hacker Information.

FBot is the most recent addition to the record of cloud hacking instruments like AlienFox, GreenBot (aka Maintance), Legion, and Predator, the latter 4 of which share code-stage overlaps with AndroxGh0st.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


SentinelOne explained FBot as “similar but distinct from these people,” owing to the actuality that it does not reference any source code from AndroxGh0st, whilst it exhibits similarities with Legion, which first came to mild very last calendar year.

Cybersecurity

The conclusion purpose of the resource is to hijack cloud, SaaS, and web solutions as very well as harvest qualifications to get hold of original obtain and monetize it by providing the obtain to other actors.

FBot, in addition to generating API keys for AWS and Sendgrid, packs an assortment of features to crank out random IP addresses, operate reverse IP scanners, and even validate PayPal accounts and the email addresses associated with individuals accounts.

“The script initiates the Paypal API ask for through the web-site hxxps://www.robertkalinkin.com/index.php, which is a Lithuanian manner designer’s retail revenue internet site,” Delamotte observed. “Interestingly, all identified FBot samples use this internet site to authenticate the Paypal API requests, and various Legion Stealer samples do as perfectly.”

On major of that, FBot packs in AWS-particular characteristics to check for AWS Uncomplicated Email Company (SES) email configuration particulars and establish the specific account’s EC2 service quotas. The Twilio-linked operation, similarly, is used to acquire specifics about the account, specifically the stability, currency, and phone figures linked to the account.

The characteristics really don’t stop there, for the malware is also able of extracting credentials from Laravel surroundings information.

Cybersecurity

The cybersecurity agency claimed it uncovered samples beginning from July 2022 to as lately as this month, suggesting that it is getting actively applied in the wild. That said, it is really at present not recognised if the tool is actively maintained and how it is really distributed to other players.

“We discovered indications that FBot is the product of personal advancement operate, so modern day builds could be dispersed by way of a smaller sized scale procedure,” Delamotte explained.

“This aligns with the concept of cloud attack equipment staying bespoke ‘private bots’ tailored for the specific consumer, which is a theme prevalent between AlienFox builds.”

Observed this report fascinating? Follow us on Twitter  and LinkedIn to browse extra exclusive information we publish.


Some sections of this article are sourced from:
thehackernews.com

Previous Post: «there is a ransomware armageddon coming for us all There is a Ransomware Armageddon Coming for Us All
Next Post: New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems new poc exploit for apache ofbiz vulnerability poses risk to»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.