Security News > 2021 > March > New botnet targets network security devices with critical exploits

Authors of a new botnet are targeting connected devices affected by critical-level vulnerabilities, some of them impacting network security devices.
Successfully compromised devices end up with a variant of the Mirai botnet malware specific to the architecture of the device.
In mid-February, security researchers at Palo Alto Networks' Unit 42 discovered attacks from this botnet and started to track its activity.
It took about a month for the botnet operator to integrate exploits for ten vulnerabilities, many of them critical, for various targets.
There are more recent exploits leveraged in these attacks, like CVE-2021-22502, a remote code execution bug in the Micro Focus Operation Bridge Reporter product from Vertica.
Unit 42 researchers say that three of the vulnerabilities the attackers exploit have yet to be identified as the targets remain unknown.
News URL
Related news
- Malware botnets exploit outdated D-Link routers in recent attacks (source)
- New Mirai botnet targets industrial routers with zero-day exploits (source)
- Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks (source)
- The ongoing evolution of the CIS Critical Security Controls (source)
- Security pros baited with fake Windows LDAP exploit traps (source)
- Hackers exploit critical Aviatrix Controller RCE flaw in attacks (source)
- Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet (source)
- Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution (source)
- Hackers exploit critical unpatched flaw in Zyxel CPE devices (source)
- New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-08 | CVE-2021-22502 | OS Command Injection vulnerability in Microfocus Operation Bridge Reporter 10.40 Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. | 9.8 |