Security News > 2023 > November > Mirai malware infects routers and cameras for new botnet

Akamai has uncovered two zero-day bugs capable of remote code execution, both being exploited to distribute the Mirai malware and built a botnet army for distributed denial of service attacks.
Because the security holes aren't plugged yet, Akamai's Security Intelligence Response Team did not name the brands or the affected devices.
The camera vendor produces about 100 network video recorder, DVR, and IP products, and although the zero-day targets one specific model, Akamai says a sub-variant model of the device is "Likely" also vulnerable.
"The feature being exploited is a very common one, and it's possible there is code reuse across product line offerings," according to the Akamai Security Intelligence Response Team's advisory.
Akamai's researchers monitor botnet activity using a global network of honeypots but didn't spot the new Mirai variant until October - and didn't know which devices it was targeting until November 9.
It primarily uses older JenX Mirai code, although Akamai noted some samples it spotted were linked to the hailBot Mirai variant.
News URL
https://go.theregister.com/feed/www.theregister.com/2023/11/23/zeroday_routers_mirai_botnet/
Related news
- MikroTik botnet uses misconfigured SPF DNS records to spread malware (source)
- 13,000 MikroTik Routers Hijacked by Botnet for Malspam and Cyberattacks (source)
- Mirai Variant Murdoc_Botnet Exploits AVTECH IP Cameras and Huawei Routers (source)
- Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13,000+ IoT Devices (source)
- Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet (source)
- Mirai botnet behind the largest DDoS attack to date (source)
- Juniper enterprise routers backdoored via “magic packet” malware (source)
- Why is my Mitel phone DDoSing strangers? Oh, it was roped into a new Mirai botnet (source)
- New Aquabotv3 botnet malware targets Mitel command injection flaw (source)
- Vo1d malware botnet grows to 1.6 million Android TVs worldwide (source)