Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The module exploits CVE-2020-11651, which is an authentication bypass that results in full remote command execution as root.
This command exploits a disputed vulnerability CVE-2019-9193 that allows users with pg_execute_server_program privileges to execute arbitrary code. However, this behavior is considered to be a “feature” by PostgreSQL developers.
In May 2023, a vulnerability affecting RocketMQ servers (CVE-2023-33246), which allows remote code execution, was publicly disclosed... Juniper Threat Labs has detected multiple attacks where threat actors took advantage of the vulnerability to infiltrate systems and subsequently install the malicious DreamBus bot. | Juniper Threat Labs has detected multiple attacks where threat actors took advantage of the vulnerability to infiltrate systems and subsequently install the malicious DreamBus bot, a malware strain last seen in 2021.
Metabase Exploit Module (CVE-2023-38646) ... The open source versions of Metabase 0.46.6.1 and earlier, as well as Metabase Enterprise 1.46.6.1 and earlier, are vulnerable to CVE-2023-38646 ... The vulnerability allows an attacker to execute arbitrary commands on the server. The DreamBus exploit targeting the vulnerability is likely based on an open source proof-of-concept. | Each module scans for servers listening on specific ports, performs exploitation, and if successful, executes shell scripts that download the main DreamBus module, which in turn deploys XMRig to mine Monero cryptocurrency.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
If either the IT automation tools or SSH public key authentication attempts are successful, the main DreamBus spreader module will execute a series of commands on the remote system to retrieve the username, computername, architecture, and external IP address, compute an MD5 hash of the system’s network IP addresses, and list that user’s cron jobs.
For each host, the module tries to authenticate as root using trusted SSH public key authentication... It then tries to authenticate to each remote server with the username of the compromised account with SSH public key authentication
MITRE ATT&CK Table Tactic Technique T1133 External Remote Services
These techniques include numerous modules that exploit implicit trust, weak passwords, and unauthenticated remote code execution (RCE) vulnerabilities in popular applications... At the time of publication, Zscaler ThreatLabZ has observed modules designed to spread through SSH, PostgreSQL, Redis, Hadoop YARN, Apache Spark, HashiCorp Consul, and SaltStack.
The function x() is used to establish persistence by creating a cron job that runs once per hour... The Redis module... create cron jobs that will be executed every minute... The SaltStack module... writes the following lines for a cron job
Furthermore, a cron job ... is created and configured to execute the downloader script with the same hourly frequency.
The function x() is used to establish persistence by creating a cron job that runs once per hour... The Redis module... create cron jobs that will be executed every minute... The SaltStack module... writes the following lines for a cron job
Furthermore, a cron job ... is created and configured to execute the downloader script with the same hourly frequency.
For each host, the module tries to authenticate as root using trusted SSH public key authentication... It then tries to authenticate to each remote server with the username of the compromised account with SSH public key authentication
The function x() is used to establish persistence by creating a cron job that runs once per hour... The Redis module... create cron jobs that will be executed every minute... The SaltStack module... writes the following lines for a cron job
Furthermore, a cron job ... is created and configured to execute the downloader script with the same hourly frequency.
Each DreamBus ELF binary is packed by UPX with a modified header and footer. This alteration is designed to obfuscate the malware’s code... The magic bytes UPX! are typically replaced with non-ASCII values.
Each DreamBus module is an Executable and Linkable Format (ELF) binary that is packed by UPX with a modified header and footer. This alteration is designed to prevent the UPX command-line tool from statically unpacking DreamBus binaries.
Many DreamBus plugins share code, for example, to create a lock file named 22 in the directory /tmp/.X11-unix/ and most set the name of the calling thread to tracepath. This is intended to disguise the DreamBus modules and make them appear to be legitimate
“They can also scan for exploitable vulnerable remote services once inside the VPC.”
“when attackers gain initial access and compromise a workload, they can abuse IAM permissions or ‘hop’ from one workload to another within the virtual private cloud (VPC)”
the bot can send requests to the following paths: ... /ping ... /mine ... /cmd1 ... /kill
Most command-and-control (C&C) components are hosted through TOR or on an anonymous file-sharing service such as oshi[.]at and leverage the HTTP protocol... DreamBus will use a proxy service such as tor2web to translate requests between TOR and the internet
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DreamBus is a Linux ELF bot malware delivered after exploitation of RocketMQ CVE-2023-33246. It downloads and executes additional modules from a TOR hidden service, supports beaconing and remote script execution, can install a Monero miner, spreads laterally using SSH and IT automation tools such as ansible, knife, salt, and pssh, and establishes persistence via systemd timer services and cron jobs.
DreamBus is a modular Linux ELF malware family packed with modified UPX headers/footers. Its exploit modules scan internal RFC1918 and public IP ranges, exploit exposed services including Metabase and RocketMQ, brute-force some services such as Redis, PostgreSQL, and SSH, then download the main module, which deploys XMRig for Monero mining.
Botnet observed exploiting Apache RocketMQ RCE (CVE-2023-33246) to deploy cryptocurrency mining payloads on vulnerable servers.
Botnet cited as an example of a worm that can infect cloud workloads, scan other VPC workloads for exploitable vulnerabilities or misconfigurations, and target weak authentication.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.