Sony Pixel Power calrec Sony

Akamai Warns of IptabLes and IptabLex Infection on Linux, DDoS attacks

03/09/2014

September 03, 2014 Akamai Warns of IptabLes and IptabLex Infection on Linux, DDoS attacks

Akamai Contacts Rob Morton

Media Relations

617-444-3641

rmorton@akamai.com

or Tom Barth

Akamai Investor Relations

617-274-7130

tbarth@akamai.com

Linux systems infiltrated and controlled in a DDoS botnet

Entertainment industry targeted by DDoS attacks

Large and growing botnet believed to be expanding from Asia to more regions

CAMBRIDGE, Mass - September 3, 2014 - Akamai Technologies, Inc. (NASDAQ: AKAM), the leading provider of cloud services for delivering, optimising and securing online content and business applications, today released, through the companys Prolexic Security Engineering & Research Team (PLXsert), a new cybersecurity threat advisory. The advisory alerts enterprises to a high-risk threat of IptabLes and IptabLex infections on Linux systems. Malicious actors may use infected Linux systems to launch distributed denial of service (DDoS) attacks against the entertainment industry and other verticals. The advisory is available for download from Prolexic (now part of Akamai) at www.prolexic.com/iptablex.

We have traced one of the most significant DDoS attack campaigns of 2014 to infection by IptabLes and IptabLex malware on Linux systems, said Stuart Scholly, senior vice president and general manager, Security Business Unit, Akamai. This is a significant cybersecurity development because the Linux operating system has not typically been used in DDoS botnets. Malicious actors have taken advantage of known vulnerabilities in unpatched Linux software to launch DDoS attacks. Linux admins need to know about this threat to take action to protect their servers.

DDoS botnet threat to Linux systems

The mass infestation of IptabLes and IptabLex seems to have been driven by a large number of Linux-based web servers being compromised, mainly by exploits of Apache Struts, Tomcat and Elasticsearch vulnerabilities. Attackers have used the Linux vulnerabilities on unmaintained servers to gain access, escalate privileges to allow remote control of the machine, and then drop malicious code into the system and run it. As a result, a system could then be controlled remotely as part of a DDoS botnet.

A post-infection indication is a payload named .IptabLes or. IptabLex located in the /boot directory. These script files run the .IptabLes binary on reboot. The malware also contains a self-updating feature that causes the infected system to contact a remote host to download a file. In the lab environment, an infected system attempted to contact two IP addresses located in Asia.

Asia apparently a significant source of DDoS attacks

Command and control centers (C2, CC) for IptabLes and IptabLex are currently located in Asia. Infected systems were initially known to be in Asia; however, more recently many infections were observed on servers hosted in the U.S. and in other regions. In the past, most DDoS bot infections originated from Russia, but now Asia appears to be a significant source of DDoS development.

Prevention, detection and DDoS mitigation

Detecting and preventing an IptabLes or IptabLex infestation on Linux systems involves patching and hardening Linux servers and antivirus detection. In the threat advisory, PLXsert provides bash commands to clean an infected system.

DDoS mitigation for the target of a DDoS attacker who controls these infected bots may include rate-limiting DDoS mitigation techniques. In addition, PLXsert shares a YARA rule in the threat advisory to identify the ELF IptabLes payload used in an observed attack campaign.

The IptabLes and IptabLex botnet has produced significant DDoS attack campaigns for which target companies have sought expert DDoS protection. Akamai offers DDoS mitigation solutions to stop DDoS attacks launched from IptabLes and IptabLex bots.

PLXsert anticipates further infestation and the expansion of this DDoS botnet.

Get the IptabLes and IptabLex DDoS Bot Threat Advisory to learn more

In the advisory, PLXsert shares its analysis and details about Iptables and IptabLes infections, including:

Indicators of infection

Analysis of the binary (ELF) associated with IptabLes and IptabLex infections

Payload initialization, entrenchment and persistence

Network code analysis

Case study of a DDoS attack campaign

How to hardening Linux servers against this threat

Antivirus detection rates

Bash commands to clean an infected system

YARA rule to identify an ELF IptabLes payload

DDoS mitigation techniques

A complimentary copy of the threat advisory is available for download at www.prolexic.com/iptablex.

About Akamai

Akamai is the leading provider of cloud services for delivering, optimising and securing online content and business applications. At the core of the Companys solutions is the Akamai Intelligent Platform , providing extensive reach, coupled with unmatched reliability, security, visibility and expertise. Akamai removes the complexities of connecting the increasingly mobile world, supporting 24/7 consumer demand, and enabling enterprises to securely leverage the cloud. To learn more about how Akamai is accelerating the pace of innovation in a hyperconnected world, please visit www.akamai.com or blogs.akamai.com, and follow @Akamai on Twitter.

Top
LINK: http://uk.akamai.com/html/about/press/releases/2014/press-090314-1.htm...
See more stories from akami

Most recent headlines

09/11/2025

Dalet Unveils Agentic AI Media Workflows at IBC2025

Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...

04/11/2025

Broadcasting is Too Important to Fail

Fred Baumgartner's op-ed (ATSC 3.0: I Cant Imagine Anyone Defending Our Current Adoption Strategy) on the broadcast industry's transition to ATSC 3.0 dr...

04/11/2025

Q&A with Music Alum Andrew van der Paardt

Q&A with Music Alum Andrew van der Paardt The oboist and English horn player reports back from the pit of the New York City Ballet Orchestra, and tells how he...

04/11/2025

November 03, 2025

Douglas W. Phillips and Steven M. Paul join Scripps Research Board of Directors Finance and biomedical leaders bring decades of experience in investment strateg...

03/11/2025

SVG Sit-Down: Inside the Sports Rights Landscape (and the new IMG) with Andrew Demsey, IMG SVP, North America Rights

SVG Sit-Down: Inside the Sports Rights Landscape (and the new IMG) with Andrew D...

03/11/2025

Challenging the Norm: How TNT Sports is Evolving Coverage of the Men's and Women's FA Cups With a Fresh Approach

Challenging the norm: How TNT Sports is evolving coverage of the men's and w...

03/11/2025

Inspired Storytelling: TNT Sports' Pete Thomas on Creating Opportunities Out of Challenges for the FA Cups

Inspired storytelling: TNT Sports' Pete Thomas on creating opportunities out...

03/11/2025

NBA 2K League Returns With New Format Featuring NBA Players, Creators, and Fans

NBA 2K League Returns With New Format Featuring NBA Players, Creators, and FansSeason will include online tournaments, in-person events, and open-ladder fan com...

03/11/2025

Live on the Water: The Rowing Channel Pulls Off Historic Production at Head Of The Charles Regatta

Live on the Water: The Rowing Channel Pulls Off Historic Production at Head Of T...

03/11/2025

L3Harris and ESL Labs: A Strategic Investment in Canada's Defence Future

Strategic partnership to expand specialized testing equipment, advance national security and support regional economic growth...

03/11/2025

How Will the FCC's Busy Fall Agenda Impact Broadcasters?

In less than two weeks during late September and early October, the Federal Communications Commission acted on two proposed rulemakings that could have an enorm...

03/11/2025

NAB's Josh Miely Named VP of Technology, Programming and Education

Josh Miely is returning to a more hands-on radio and TV role with the National Association of Broadcasters....

03/11/2025

All You Need to Know About MXL

Broadcasters have spent years trying to integrate different vendor technologies in their facilities. As the industry has moved closer to software, that struggle...

03/11/2025

The Battle to Protect Broadcast Content From AI Has Just Begun

As the malevolent siege against broadcasters' interests intensifies from the far reaches of artificial intelligence misuse to relentless innovation in the m...

03/11/2025

Gary Snow Plans to Retire From Wheatstone

Wheatstone founder and owner Gary Snow will retire from the company by the end of next year....

03/11/2025

Hybrid, AI Are Guiding the Measurement of TV Viewership

In ye olde days of traditional television, when U.S. TV viewing options were limited to ABC, CBS, NBC and PBS, Nielsen's paper diaries were sufficient for t...

03/11/2025

NVIDIA Partners Bring Physical AI, New Smart City Technologies to Dublin, Ho Chi Minh City, Raleigh and More

Two out of every three people are likely to be living in cities or other urban c...

03/11/2025

Trailer & poster unveiled for Sky Original festive family feature film Tinsel Town

Monday 3 November 2025 To view this content, please enable our use of cookies. ...

03/11/2025

Rohde & Schwarz acquires open source intelligence specialist Munich Innovation Labs GmbH

Rohde & Schwarz acquires open source intelligence specialist Munich Innovation L...

03/11/2025

Rohde & Schwarz launches revolutionary super wideband mobile network scanner, setting new standard for 5G

Rohde & Schwarz launches revolutionary super wideband mobile network scanner, se...

03/11/2025

Nokia and Rohde & Schwarz collaborate on AI-powered 6G receiver to cut costs, accelerate time to market

Nokia and Rohde & Schwarz collaborate on AI-powered 6G receiver to cut costs, ac...

03/11/2025

A4ESSOR and OCCAR sign new procurement contract to advance development of interoperable tactical communication

A4ESSOR and OCCAR sign new procurement contract to advance development of intero...

03/11/2025

Sitep Australia joins Rohde & Schwarz team for Hunter class frigate communications

Sitep Australia joins Rohde & Schwarz team for Hunter class frigate communicatio...

03/11/2025

Famke Janssen Stars as Betty Jonkers in "Forever Pour Toujours" Music Video

Back to All News Famke Janssen Stars as Betty Jonkers in "Forever Pour Toujours" Music Video Entertainment 03 November 2025 GlobalNetherlandsBelgium Link c...

03/11/2025

Red Seat Ventures and The 33rd Team Announce Exclusive Sales Partnership

Red Seat Ventures and The 33rd Team Announce Exclusive Sales Partnership Red Seat Ventures to Spearhead Sales Representation for The 33rd Team's Dynamic S...

03/11/2025

Brand New RT Documentary Series Tonight New RT Documentary Series Trackers: The People v The Banks

They've made that decision and ruined an awful lot of people's lives. ...

02/11/2025

Space42 Expands Earth Observation Constellation, Foresight, with Launch of Three New SAR Satellites

Abu Dhabi, UAE November 2, 2025: Space42 (ADX: SPACE42), the UAE-based AI-powe...

01/11/2025

Thunderbolt 3 and Symphony MkII

Thunderbolt 3 Now Standard on Symphony MkII - Starting November 11 Beginning November 11, all new Apogee Symphony I/O MkII units will ship with Thunderbolt 3 as...

01/11/2025

Expanding Symphony Desktop Using ADAT

How to Expand the Apogee Symphony Desktop with Cranborne 500ADAT Want to expand your Symphony Desktop beyond two inputs? Whether you're tracking a full drum...

01/11/2025

aconnic AG releases Half Year Financial Report 2025 and implements Change Measures

aconnic AG (ISIN: DE000A0LBKW6), Munich, has published the Financial Report for ...

01/11/2025

tvONE and Matrox Video Partner to Deliver Flawless AV-ove...

tvONE is proud to announce a strategic partnership with Matrox Video, combining CALICO PRO's high-performance video processing with the Matrox ConvertIP Ser...

01/11/2025

CJP Broadcast Joins Grass Valley Partner Programme to Str...

CJP Broadcast has joined the Grass Valley partner programme as both a Systems Integration Partner and AMPP Partner. The collaboration enhances CJP's ability...

01/11/2025

TAG Video Systems Earns Dual Recognition for ESG Initiati...

TAG Video Systems, the leader in software-based IP end-to-end workflow monitoring, deep probing, and real-time visualization, has earned a higher-rated DPP Comm...

01/11/2025

Operative Announces New CEO to Drive Next Phase of Growth

Michael Napodano Appointed New CEO Of Operative Media Operative today announced the appointment of Mike Napodano as Chief Executive Officer, marking the next s...

01/11/2025

Cine Gear Expo Atlanta 2025 Success at Trilith Studios

Film industry professionals flocked to Cine Gear Expo Atlanta 2025 at celebrated Trilith Studios in Fayetteville, Georgia, on October 3 and 4. Back for its 6th ...

01/11/2025

Christopher Ross BSC and 300 Asteras Light the Border Cro...

Photo courtesy of Peacock and Sky Christopher Ross, BSC, began his cinematic obsession early. He cites reading Scorsese on Scorsese as a teenager with teaching...

01/11/2025

ITN, Magnite Launch New Private Marketplace for Local Linear TV

NEW YORK ITN and the sell-side advertising company Magnite have announced the launch of what they are billing as the industrys first Local Linear TV Private Mar...

01/11/2025

Netflix Unveils Operation Safed Sagar' at the Inaugural Sekhon Indian Air Force Marathon 2025

Back to All News Netflix Unveils Operation Safed Sagar' at the Inaugural S...

01/11/2025

Netflix Announces Partnership With Yash Raj Films, Bringing Iconic Bollywood Titles to the Platform

Back to All News Netflix Announces Partnership With Yash Raj Films, Bringing Ic...

31/10/2025

FanDuel Sports Network To Deliver Selected Live NBA, NHL Games to Major Streaming Services for In-Market Viewers

FanDuel Sports Network To Deliver Selected Live NBA, NHL Games to Major Streamin...

31/10/2025

NBC Jumps Out of the Gate in Extended Breeder's Cup Deal With Dual Drones, Jockey Cams, RF Super-Mo

NBC Jumps Out of the Gate in Extended Breeder's Cup Deal With Dual Drones, J...

31/10/2025

Tribute: Remembering Segomotso Keorapetse (28 May 1968 22 October 2025)

FOR IMMEDIATE RELEASE 30 October 2025 It is with great sadness that we mourn the passing of Segomotso Keorapetse, an award- winning South African television d...

31/10/2025

Nexstar Extends Chairman and CEO Perry Sook Through 2029

IRVING, Texas As station groups move into an era that promises rapid tech, regulatory and economic changes, Nexstar Media Group said its board has extended chai...

31/10/2025

Late Night Thrives on Social Media With Billions of Views in 2025

While some analysts have questioned the ongoing economic viability of broacast-TV late night shows amid ongoing declines in linear viewing, new data from Tubula...

31/10/2025

Disney Programming Dropped From YouTube TV

The contentious contract negotiations between The Walt Disney Co. and YouTube TV have resulted in a blackout of Disney-owned programming on the pay TV operator....

31/10/2025

tvONE Integrates CALICO PRO Video Processing With Matrox ConvertIP Series

CINCINNATI Video conversion and AV signal distribution specialist tvONE and Matrox Video have struck a strategic partnership, combining CALICO PRO's video p...

31/10/2025

IAB Urges Standards for CTV Ad Measurement

NEW YORK The Interactive Advertising Bureau (IAB) today released a new industry guide that discusses the urgency of adopting new standards that will help advert...

31/10/2025

Late Night Shows Thrive on Social Media with Billions of Views in 2025

While some analysts have questioned the ongoing economic viability of late night shows on broadcast TV amid ongoing declines in linear viewing, new data from Tu...

31/10/2025

Berklee Celebrates the Inauguration of President Jim Lucchese

Berklee Celebrates the Inauguration of President Jim Lucchese In his inaugural address, Lucchese shared an optimistic vision for Berklee's future as a for...