Security News > 2022 > September > Moobot botnet is coming for your unpatched D-Link router

Moobot botnet is coming for your unpatched D-Link router
2022-09-06 20:40

The Mirai malware botnet variant known as 'MooBot' has re-emerged in a new attack wave that started early last month, targeting vulnerable D-Link routers with a mix of old and new exploits.

MooBot was discovered by analysts at Fortinet in December 2021, targeting a flaw in Hikvision cameras to spread quickly and enlist a large number of devices into its DDoS army.

MooBot's operators leverage the low-attack complexity of the flaws to gain remote code execution on the targets and fetch the malware binary using arbitrary commands.

Eventually, the captured routers participate in directed DDoS attacks against various targets, depending on what MooBot's operators wish to achieve.

Users of compromised D-Link devices may notice internet speed drops, unresponsiveness, router overheating, or inexplicable DNS configuration changes, all common signs of botnet infections.

The best way to shut the door to MooBot is to apply the available firmware updates on your D-Link router.


News URL

https://www.bleepingcomputer.com/news/security/moobot-botnet-is-coming-for-your-unpatched-d-link-router/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
D Link 111 1 30 30 39 100