Chuck Norris Botnet Affects Linux Routers

Feb 23, 2010

Researchers at the University of Masaryk in Brno, Czech Republic, have detected a botnet that can hit Linux routers and DSL modems.

According to an article in the Prague Daily Monitor, researchers detected the trojan while working on securing the Czech national defense ministry, known as CYBER, against Internet attacks.

Head of the security project Jan Vykopal identified the suspect as a self-perpetuating trojan that first and foremost attacks Linux routers and DSL modems with weak usernames and passwords. The botnet was first detected in a D-Link device, Vykopal revealed in a PCWorld article. Next to MIPS-based Linux devices, the Chuck Norris botnet can also affect satellite TV receivers.

The botnet found its first martial arts moves from a server out of Italy, getting its name from a bit of source code with the line "in nome di Chuck Norris." It was immediately removed from the Net after its discovery and reporting. Since then, however, a number of copies have been identified worldwide. Infected devices are notably in Europe, South America and China, with the exact number not known.

The botnet's main objective is to gather passwords and access to Internet banking, online shops and related sites

Just Say No. The Chuck Norris botnet lives in the router's RAM, so a simple restart will remove it. The easiest way to avoid any further attacks through the Web interface is by using a strong password on the router or modem.

Related content

  • Psyb0t Attacks Linux Routers (Update)

    A botnet named psyb0t has been nesting for a few months in consumer devices that run on Linux with MIPS CPUs, notably routers. Infested devices connect through a botnet over a private Internet Relay Chat (IRC) server to await commands.

  • Psyb0t Attacks Linux Routers

    A botnet named psyb0t has been nesting for a few months in consumer devices that run on Linux with MIPS CPUs, notably routers. Infested devices connect through a botnet over a private Internet Relay Chat (IRC) server to await commands.

  • Helping Hands

    In true open hardware spirit, Social Hardware looks to produce a development kit for prosthetic hands to help rural amputees in India.

  • Million Linux Kernels Simulate Botnet

    The biggest botnet to date is being virtualized using a network of one million Linux kernels. The virtual machines form an experiment in studying the origins of the malware.

  • Botnet of Linux Servers with Dynamic IP Discovered

    A Russian Web developer has found a network of a couple of hundred Linux servers that could distribute malware to Windows systems.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More

News