Security News > 2023 > November > New botnet malware exploits two zero-days to infect NVRs and routers
![New botnet malware exploits two zero-days to infect NVRs and routers](/static/build/img/news/new-botnet-malware-exploits-two-zero-days-to-infect-nvrs-and-routers-medium.jpg)
A new Mirai-based malware botnet named 'InfectedSlurs' has been exploiting two zero-day remote code execution vulnerabilities to infect routers and video recorder devices.
The malware hijacks the devices to make them part of its DDoS swarm, presumably rented for profit.
The botnet leverages an undocumented RCE flaw to gain unauthorized access to the device.
"The SIRT did a quick check for CVEs known to impact this vendor's NVR devices and was surprised to find that we were looking at a new zero-day exploit being actively leveraged in the wild," reads Akamai's report.
Looking closer into the campaign, Akamai discovered that the botnet also targets a wireless LAN router popular among home users and hotels, which suffers from another zero-day RCE flaw leveraged by the malware.
Given the lack of a patch for the affected devices, rebooting your NVR and rooter devices should temporarily disrupt the botnet.
News URL
Related news
- Malware botnets exploit outdated D-Link routers in recent attacks (source)
- New Mirai botnet targets industrial routers with zero-day exploits (source)
- Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet (source)
- New botnet exploits vulnerabilities in NVRs, TP-Link routers (source)
- Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks (source)
- New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP (source)
- Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection (source)
- Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware (source)
- Juniper warns of Mirai botnet targeting Session Smart routers (source)
- Juniper warns of Mirai botnet scanning for Session Smart routers (source)