Uncovering HinataBot: An Investigation Into a Go-Based Threat
Over the past several years, malicious actors have increasingly utilized languages like Go to craft specialized payloads that could run across multiple architectures and operating systems. Akamai recently identified HinataBot, a Go-based botnet that exploits old vulnerabilities and weak credentials to launch DDoS attacks. This malware was observed being distributed via HTTP and SSH honeypots.
1. Detecting HinataBot
Uncovering HinataBot: A Deep Dive into a Go-Based Threat
Akamai’s Security Intelligence Response Team (SIRT) recently identified HinataBot as a new Go-based botnet. This DDoS threat targets Realtek SDK devices, Huawei HG532 routers, and exposed Hadoop YARN servers by recruiting devices into an attack swarm for massive attacks.
The botnet relies on outdated vulnerabilities, including CVE-2014-8361 and CVE-2017-17215, to infect devices. Attackers may utilize Remote Code Execution (RCE) techniques to compromise publicly exposed Hadoop YARN ResourceManager instances before moving onto more sensitive systems.
HinataBot, like many Go-based threats, was developed by cybercriminals who take advantage of its high performance, multithreading capabilities and operating system cross-compilation support. These characteristics enable it to launch DDoS attacks that can cripple even the largest network infrastructures.
HinataBot is still under development, so it is likely that threat actors will add additional exploits and broaden its targeting capabilities. Therefore, it is essential to constantly monitor these emerging risks and update firmware on affected products in order to stay ahead of any attacks that arise.
Additionally, organizations can utilize IOCs to gain more insight into APTs and their current attack patterns. Doing so allows organizations to identify potential mitigation measures against this threat while safeguarding the environment against future attacks.
Go-based malware has been increasingly noticed and popular with cybercriminals due to its high performance, ease of multithreading, operating system cross-compilation support, and ability to add complexity to binaries.
3. Identifying HinataBot’s Command-Line Interface
A closer look at the HinataBot binaries revealed a bevy of useful gadgets. The most impressive device in the box was an octobox with more than 50 smaller components, plus an attractive control panel to put it all to good use. With our command console, we were able to quickly assemble all of the above devices, test their functionality, and provide our clients with a truly unique and uncompromised end user experience – without them even knowing we were spying on them! After the stinger was taken away, our clients were able to take home some of the finest goods in the business without any hassle thanks to a dedicated team of specialists that never cease smiling and always have an upbeat strategy for getting to their next big thing.
4. Identifying HinataBot’s Vulnerabilities
Uncovering HinataBot: A Deep Dive into a Go-Based Threat
Akamai’s Security Intelligence Response Team (SIRT) recently identified a botnet that uses old vulnerabilities and weak credentials from HTTP and SSH honeypots to infect routers, web servers, and poorly configured SSH endpoints. Nicknamed HinataBot after an anime character from Naruto, this botnet uses multiple attack methods including exploiting arbitrary code execution flaws in Realtek SDK devices (CVE-2014-8361), Huawei HG532 routers (CVE-2017-17215) as well as exposed Hadoop YARN servers with weak credentials.
This new threat is built upon Go, an open source programming language which has become popular with cybercriminals due to its high performance, ease of multi-threading and cross-compilation support. Recently, several Go-based botnets such as GoBruteForcer have been observed in the wild that have used multiple web servers to launch targeted attacks.
Unfortunately, botnets like HinataBot are notoriously difficult to decipher and reverse engineer. Fortunately, SIRT is actively investigating and monitoring emerging threats like HinataBot in order to provide organizations with better protection for their network infrastructures.
HinataBot’s most recent version has significantly limited its attack surface to certain protocols, such as HTTP and UDP, by employing RCE payloads for known vulnerabilities. This indicates the authors are working hard to make their botnet more difficult to reverse engineer and detect.
HinataBot is a variant of Mirai that has been rewritten in Golang. Like Mirai, HinataBot relies on brute-forcing weak passwords and infection scripts to infect devices; however, unlike Mirai it also offers a command-line interface which enables attackers to control the botnet without using an operating system. As this threat continues to evolve and develop it’s important for security researchers and IOCs (Initial Coin Offerings) to continue monitoring it and utilize IOCs (Initial Cases) for detecting attack traffic as it grows.
5. Identifying HinataBot’s Distribution Methods
Uncovering HinataBot: A Deep Dive into a Go-Based Threat
Akamai Security Intelligence Team recently identified “HinataBot,” an automated Go-Based botnet using older CVEs to access routers, web servers and poorly configured SSH servers. This sample leverages HTTP, UDP and TCP protocols in order to perform distributed denial-of-service (DDoS) attacks against various targets.
Although the malware has been observed with various distribution methods, such as dialing out and listening for incoming connections, the most recent version has confined its attack methods to HTTP and UDP attacks only. This differs from earlier versions which employed multiple protocols and utilized various infection scripts.
However, the authors have identified two primary vulnerabilities for HinataBot’s distribution methods: an arbitrary code execution vulnerability in a miniigd SOAP service within Realtek SDK devices (CVE-2014-8361) and exposure of exposed Hadoop YARN servers with weak credentials. Although these haven’t been fully exploited yet by other threat actors, these two flaws remain open-source.
Hinata Hyuga, a member of Konohagakure’s Hyuga clan, was once seen as a failure by her father due to her gentle demeanor. But with Naruto by her side, Hinata hopes to gradually transform herself – even if only slightly.
As Hinata continues her training with Team Kurenai, her confidence grows and she learns to overcome her fears by following Naruto’s example. This admiration for Naruto’s enthusiasm, optimism and unyielding commitment to protecting those he cares about most has inspired Hinata to hone her skills and become a chunin; moreover, she has fallen in love with Naruto and will do anything necessary to safeguard him.


