New Mirai Botnet Targets Industrial Routers

Teilen:

Security researchers warn of a new variant of the Mirai botnet. Attackers used it for zero-day exploits on industrial routers.

According to security analyses, the Gayfemboy botnet, based on the infamous Mirai malware, is currently spreading around the world. Researchers at Chainxin X Lab found that cybercriminals have been using the botnet to attack previously unknown vulnerabilities since November 2024. The botnet’s preferred targets include Four-Faith and Neterbit branded routers or smart home devices.

In this context, experts from VulnCheck reported at the end of December of a vulnerability in Four-Faith industrial routers (CVE-2024-12856) that was exploited in the wild. The attackers exploited the router’s default credentials to start a remote command injection.

In addition, the botnet has been used for targeted attacks on unknown vulnerabilities in Vimar Neterbit routers and smart home devices. According to Chainxin X Lab, Gayfemboy is used for a total of 20 vulnerabilities and weak telnet passwords. It has a brute force module for insecure telnet passwords, uses custom UPX packing with unique signatures, and implements Mirai-based command structures. This allows the attackers to update clients, scan networks and carry out DDoS attacks.

Targets

According to the researchers, the botnet has been attacking hundreds of targets every day since its discovery in February 2024. The number of daily active bot IPs is 15,000, most of which are located in China, the USA, Russia, Turkey and Iran. The targets of attacks are spread all over the world and affect different industries. The main targets are in China, the United States, Germany, the United Kingdom, and Singapore.

According to Chainxin X Lab, while the botnet’s DDoS attacks are short-lived (between 10 and 30 seconds), they have a high intensity, with the data rate exceeding 100 Gbps and can cause disruption even to robust infrastructures.

Devices at risk

According to the analysis, the botnet’s attacks target the following devices:

  • ASUS routers (via N-Day exploits).
  • Huawei routers (via CVE-2017-17215)
  • Neterbit router (custom exploit)
  • LB-Link router (via CVE-2023-26801)
  • Four-Faith Industrial Routers (via the zero-day now tracked as CVE-2024-12856)
  • PZT cameras (via CVE-2024-8956 and CVE-2024-8957 )
  • Kguard DVR
  • Lilin DVR (via remote code execution exploits)
  • Generic DVRs (using exploits such as TVT editBlackAndWhiteList RCE)
  • Vimar smart home devices (presumably exploiting an unknown vulnerability)
  • Various 5G/LTE devices (likely due to misconfigurations or weak credentials)

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:57 pm, Mai 12, 2025
Wetter-Symbol 15°C
L: 13° | H: 17°
wenige Wolken
Luftfeuchtigkeit: 79 %
Druck: 1014 mb
Wind: 1 mph NE
Windböe: 2 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 19%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:13 am
Sonnenuntergang: 8:40 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
13° | 17°°C 0.28 mm 28% 12 mph 79 % 1020 mb 0 mm/h
Mi. Mai 14 10:00 pm
Wetter-Symbol
11° | 22°°C 0 mm 0% 9 mph 74 % 1023 mb 0 mm/h
Do. Mai 15 10:00 pm
Wetter-Symbol
9° | 18°°C 0 mm 0% 12 mph 78 % 1025 mb 0 mm/h
Fr. Mai 16 10:00 pm
Wetter-Symbol
8° | 21°°C 0 mm 0% 10 mph 84 % 1026 mb 0 mm/h
Sa. Mai 17 10:00 pm
Wetter-Symbol
9° | 22°°C 0 mm 0% 9 mph 86 % 1025 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0.22 mm 22% 2 mph 78 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 3 mph 79 % 1015 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 4 mph 78 % 1017 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 8 mph 52 % 1018 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 9 mph 42 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
21° | 21°°C 0.28 mm 28% 12 mph 44 % 1018 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
18° | 18°°C 0.1 mm 10% 10 mph 43 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 60 % 1020 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,469.89
-1.69%
Ethereum(ETH)
€2,235.26
-1.46%
Fesseln(USDT)
€0.90
-0.02%
XRP(XRP)
€2.28
6.94%
Solana(SOL)
€155.76
-0.14%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.207317
-1.08%
Shiba Inu(SHIB)
€0.000014
-1.52%
Pepe(PEPE)
€0.000013
-0.12%
Peanut das Eichhörnchen(PNUT)
€0.349469
-6.44%
Nach oben scrollen