{{Short description|2016 computer malware for Linux}} {{Infobox computer virus | image = | common_name = | technical_name = | alias = Remaiten | family = | classification = | type = | subtype = | isolation_date = | origin = | author = | ports_used = | platform = Linux | file_size = | language = }} '''Remaiten''' is malware which infects Linux on embedded systems by brute forcing using frequently used default username and passwords combinations from a list in order to infect a system.<ref>{{cite web | url=http://www.securityweek.com/new-remaiten-malware-builds-botnet-linux-based-routers | title=New Remaiten Malware Builds Botnet of Linux-Based Routers | publisher=securityweek.com | date=March 30, 2016 | accessdate=6 November 2016}}</ref>
Remaiten combines the features of the Tsunami and LizardStresser (aka Torlus) malware families.<ref>{{cite web | url=http://securityaffairs.co/wordpress/45820/iot/linux-remaiten-iot-botnet.html | title=The Linux Remaiten malware is building a Botnet of IoT devices | publisher=securityaffairs.co | date=March 31, 2016 | accessdate=6 November 2016 | author=Paganini, Pierluigi}}</ref> The command and control for Remaiten are handled by IRC communications. Additionally the command and control is done by an actual IRC channel rather than only the IRC protocol. This is an improvement over bots such as Tsunami and Torlus making Remaiten a greater threat than both combined.<ref>{{cite web | url=http://news.softpedia.com/news/remaiten-is-a-new-ddos-bot-targeting-linux-based-home-routers-502434.shtml | title=Remaiten Is a New DDoS Bot Targeting Linux-Based Home Routers | publisher=Softpedia | date=Mar 31, 2016 | accessdate=6 November 2016 | author=Cimpanu, Catalin}}</ref>
To avoid detection, Remaiten tries to determine the platform of a device to download the architecture-appropriate component from the command & control server.<ref>{{cite web | url=http://www.welivesecurity.com/2016/03/30/meet-remaiten-a-linux-bot-on-steroids-targeting-routers-and-potentially-other-iot-devices/ | title=Meet Remaiten – a Linux bot on steroids targeting routers and potentially other IoT devices | date=30 Mar 2016 | accessdate=6 November 2016 | author1=Malik, Michal |author2=M.Léveillé, Marc-Etienne |website=WeLiveSecurity }}</ref>
Once Remaiten infects a device it is able to perform actions such as launching distributed denial of service attacks or download more malware on a device.<ref>{{Cite web |url=https://www.scmagazine.com/news/remaiten-linux-bot-combines-malware-features-to-target-weak-credentials |title=Remaiten Linux bot combines malware features to target weak credentials |last=Abel |first=Robert |website=SC Magazine |url-status=live |archive-url=https://web.archive.org/web/20231113204956/https://www.scmagazine.com/news/remaiten-linux-bot-combines-malware-features-to-target-weak-credentials |archive-date=Nov 13, 2023 |publication-date=March 30, 2016}}</ref> Remaiten is able to scan and remove competing bots on a system compromised by it.<ref>{{cite web | url=http://www.computerworld.com/article/3049982/security/your-linux-based-home-router-could-succumb-to-a-new-telnet-worm-remaiten.html | title=Your Linux-based home router could succumb to a new Telnet worm, Remaiten | publisher=Computerworld | date=March 31, 2016 | accessdate=9 November 2016 | archive-date=10 November 2016 | archive-url=https://web.archive.org/web/20161110111752/http://www.computerworld.com/article/3049982/security/your-linux-based-home-router-could-succumb-to-a-new-telnet-worm-remaiten.html | url-status=dead }}</ref>
==See also== * Botnet * Mirai (malware) * BASHLITE * Linux.Darlloz * Linux.Wifatch * Hajime (malware)
==References== {{Reflist}}
{{IoT Malware}} {{Hacking in the 2010s}}
Category:IoT malware Category:Linux malware Category:Botnets