Blog | G5 Cyber Security

Universal Plug n Pwn! Pinkslipbot malware exploits UPnP to help it steal credentials

A variant of Pinkslipbot is the first known malware to conduct attack campaigns using infected devices as HTTPS-based control servers. Each newly infected bot indirectly receives instructions from the malwares real command-and-control (C&C) servers. The malware is unique in its usage of port-forwarding. The only other malware known to use this technique is the dreaded Conficker worm Confickerbot. The researchers from McAfee have observed multiple. computers hosted on the same home network as well as what appears to be a public Wi-Fi hotspot.”]

Source: https://grahamcluley.com/universal-plug-n-pwn-pinkslipbot-malware-exploits-upnp-help-steal-credentials/

Exit mobile version