FBot is a New Malicious Tool Targeting AWS

A recently discovered hacking tool named FBot, developed in Python, is now targeting a range of online services including web servers, cloud platforms, content management systems, and software as a service platforms like Amazon Web Services (AWS), Microsoft 365, PayPal, Sendgrid, and Twilio.

According to security researcher Alex Delamotte, FBot comes equipped with various features such as credential harvesting for spamming attacks, tools for hijacking AWS accounts, and functionalities enabling attacks on PayPal and different SaaS accounts. Delamotte reported these findings in a document shared with IT security outlet The Hacker News.

While FBot joins the ranks of other cloud hacking tools like AlienFox, GreenBot (also known as Maintance), Legion, and Predator, it stands out as distinct due to its lack of reference to any source code from AndroxGh0st. Although it shares similarities with Legion, which was first identified last year, FBot is considered a separate entity.

The primary objective of FBot is to compromise cloud, SaaS, and web services, obtaining initial access by harvesting credentials. The hackers then seek to monetize this access by selling it to other actors in the cybercrime ecosystem.

FBot Comes Well-Equipped

FBot offers a range of features, including the generation of API keys for AWS and Sendgrid, as well as capabilities to produce random IP addresses, run reverse IP scanners, and validate PayPal accounts along with associated email addresses.

Interestingly, the script used by FBot initiates PayPal API requests through the website "hxxps://www.robertkalinkin.com/index.php," which is a retail sales website for a Lithuanian fashion designer. This is the authentication method consistently employed by all identified FBot samples and some Legion Stealer samples.

Moreover, FBot incorporates AWS-specific features to check AWS Simple Email Service (SES) email configuration details and determine the targeted account's EC2 service quotas. Twilio-related functionality is also present to gather information about the account, including balance, currency, and connected phone numbers.

Additionally, FBot has the ability to extract credentials from Laravel environment files. Researchers have identified FBot samples dating back to July 2022, indicating active use in the wild. However, it remains unclear whether the tool is actively maintained and how it is distributed among other threat actors.

January 12, 2024
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.