Live data from Hacker News

The Kimwolf botnet is stalking your local network

krebsonsecurity.com

41–50 of 59 posts

Re: The Kimwolf botnet is stalking your local network

#41
post #40

I know this may seem trivial for many here but how can regular people easily check and debug their network for stuff like this?

Regular people don't need a "secure network". Phones and computers are, by default, secure against malicious networks.

Just don't run code you download from the internet or put your passwords to important accounts into cheap devices and you'll be fine. Normally people don't the the former, but sometimes do the latter.

edit: To be clear: the bitterness in this comment comes from how many developers assume loopback is secure. However, most website are allowed to send requests to local ports on your computer (IIRC) so that assumption is basically completely false. This is forgivable, except in a world where every developer runs tons of extensions/scripts/open-source apps, and have next-to-zero blast-radius-reduction methods, it makes me sad.

Re: The Kimwolf botnet is stalking your local network

#42
I couldn't really follow the technical details of the malware from the article, so I found what seems to be the first major report on the topic:

https://blog.xlab.qianxin.com/kimwolf-botnet-en/#network-pro...

That article has a more technical lens. It focuses primarily on the size and detection evasion methods of Kimwolf, rather than some notable (and definitely not unique) method of spreading.

Without looking too deeply, I'm going to assume that this is a successful botnet because it managed to get into product supply lines at big box stores and in app store games, rather than some clever virus that is spreading across the world.

I hope someone will correct me if I am mistaken!

Re: The Kimwolf botnet is stalking your local network

#43
post #37

Earlier quoted context omitted.

Sometimes; I've seen it called client isolation or something like that. Or, yeah, if you can get under the hood it's probably as easy as one or two iptables rules (or nftables or whatever).

Is this true? For devices on the same subnet, I'm petty sure they don't even have to takl to the router. Maybe a managed switch can stop it, but I doubt most home routers have anything more than a dumb switch in them.

It depends™:) Yeah, if you have a dumb switch with devices plugged in, then the upstream router probably isn't relevant. But if you've got all devices on wifi running through a single box that's a router+switch+WAP+modem (very common in consumer home networking) then that single network box is in an excellent position to control devices talking to each other. YMMV.

Re: The Kimwolf botnet is stalking your local network

#44
post #40

I know this may seem trivial for many here but how can regular people easily check and debug their network for stuff like this?

Regular people don't need a "secure network". Phones and computers are, by default, secure against malicious networks. Just don't run code you download from the internet or put your passwords to important accounts into cheap devices and you'll be fine. Normally people don't the the former, but sometimes do the latter. edit: To be clear: the bitterness in this comment comes from how many developers assume loopback is…

Sure they can send requests but they can't receive them unless you've got misconfigured CORS. I guess there's DNS rebinding but like, idk, attack surface seems pretty small. This sort of stuff isn't really worth worrying about unless you're an idiot or likely to be the victim of a targeted attack. I happily run code off the internet all the time and it seems fine. If there's one thing that really seems like a mind virus it's the paranoia all security people get, I can't imagine living life like that. I'm ok getting pwned every few decades if the tradeoff is never worrying about this shit.

Maybe I've just gotten lucky?

(i will say putting a device not running open source software/firmware or something very locked down like a phone on your LAN is insanity, i could never)

Re: The Kimwolf botnet is stalking your local network

#45

> to relay malicious and abusive Internet traffic — such as ad fraud , account takeover attempts and mass content scraping Oh no, let me get my tiny violin! Really hard to feel bad here. For most home users (that don’t expose anything sensitive on their LAN) these boxes are not a threat, seem to be doing a useful service in providing a superior streaming service that the balkanized official ones, and also shits on in…

> sounds like a pretty good box really. You can buy a better one that does not have malware installed. So these are complete and total garbage and no sane person should run them under any circumstance. Sounds like you have a bias which has prevented you from thinking about this clearly.

> You can buy a better one that does not have malware installed.

You can buy a better one if you have the technical know-how. But if you did you'd probably be running the *arr stack anyway and not need such a box. But these boxes do work and aren't any more of a threat than your usual public Wi-Fi for the casual user who does not expose any services to the LAN.

The alarm around them is less about the threat to its owner and more about the threat to the tech ecosystem at large... which considering how hostile it is to users, shouldn't really be something they have any reason to worry about.

Re: The Kimwolf botnet is stalking your local network

#46
post #23

> to relay malicious and abusive Internet traffic — such as ad fraud , account takeover attempts and mass content scraping Oh no, let me get my tiny violin! Really hard to feel bad here. For most home users (that don’t expose anything sensitive on their LAN) these boxes are not a threat, seem to be doing a useful service in providing a superior streaming service that the balkanized official ones, and also shits on in…

Until all their accounts get pwned due to credential stuffing over this or a similar botnet - being the average person with weak, reused passwords?

The majority of accounts out there don't have anything of value. If it gets pwned the person just resets their password and calls it a day (in fact due to the lack of password manager their usual workflow is to reset the password anyway on each login since they never remember whatever variation of their shitty weak password they used).

Re: The Kimwolf botnet is stalking your local network

#47

How is it not obvious to everyone reading HN that janky Android "TV" boxes (like the article references) are a by-default threat? Like seriously, many of them are sold for stupid cheap prices like $5/ea. Or advertise unlimited movies/shows/etc for similarly unbelievable prices. Putting aside the copyright infringement aspect of it, to me it's extremely obvious "wait... _why_ am I paying so little here?". No, it's not…

It's quite obvious to everyone here. Why it's not obvious to every Senator and Representative in our Government is frustrating to an extreme. We really do need to end our enhance our trade protections one way or another.

Some people love money more than they love you

Re: The Kimwolf botnet is stalking your local network

#48

I couldn't really follow the technical details of the malware from the article, so I found what seems to be the first major report on the topic: https://blog.xlab.qianxin.com/kimwolf-botnet-en/#network-pro... That article has a more technical lens. It focuses primarily on the size and detection evasion methods of Kimwolf, rather than some notable (and definitely not unique) method of spreading. Without looking too de…

What’s the deal with that seemingly random address written out as a domain name? Brian krebb’s home address?

14 emelia terrace west roxbury ma 02132 . su

As for your assumption the OP talks about how it uses residential proxies to get into lans, I don’t think it is a supply chain attack.

Re: The Kimwolf botnet is stalking your local network

#49

How is it not obvious to everyone reading HN that janky Android "TV" boxes (like the article references) are a by-default threat? Like seriously, many of them are sold for stupid cheap prices like $5/ea. Or advertise unlimited movies/shows/etc for similarly unbelievable prices. Putting aside the copyright infringement aspect of it, to me it's extremely obvious "wait... _why_ am I paying so little here?". No, it's not…

Shit man my Pet Feeder setup a back door to my network.. ended up reverse engineering the entire tuya piece of shit just so I could keep the automatic feeder running.

Fucking everyone is spying. I started downloading and decrypting apps from the App Store. It’s a god damn nightmare. Random apps are storing keys in the keychain (thanks expo!) that never leave our apple account. They follow us forever. You can’t delete them. Well.. there’s one way but it involves backing up your phone, putting it in recovery mode, and restoring from backup.

Re: The Kimwolf botnet is stalking your local network

#50
post #40

I know this may seem trivial for many here but how can regular people easily check and debug their network for stuff like this?

Regular people don't need a "secure network". Phones and computers are, by default, secure against malicious networks. Just don't run code you download from the internet or put your passwords to important accounts into cheap devices and you'll be fine. Normally people don't the the former, but sometimes do the latter. edit: To be clear: the bitterness in this comment comes from how many developers assume loopback is…

Regular people download shit all the time though? Especially now with GPT, everyone is a programmer pasting code into command line. And how many people have IoT devices that they have to connect to WiFi? That’s total blind trust.

Every time I ask this question nobody is able to give me a solid answer :/

Post reply on HN