A new Mirai botnet variant targets DigiEver DS-2105 Pro DVRs

Teilen:

Akamai researchers discovered a new Mirai botnet variant targeting a vulnerability in DigiEver DS-2105 Pro DVRs.

Akamai researchers spotted a Mirai-based botnet that is exploiting an remote code execution vulnerability in DigiEver DS-2105 Pro NVRs.

The experts pointed out that this Mirai variant has been modified to use improved encryption algorithms. The Mirai variant incorporates ChaCha20 and XOR decryption algorithms.

A new Mirai botnet variant targets DigiEver DS-2105 Pro DVRs 1

In November 2024, the Akamai Security Intelligence Research Team (SIRT) observed increased activity targeting the URI /cgi-bin/cgi_main.cgi, linked to a Mirai-based malware campaign exploiting an unassigned RCE vulnerability in DVR devices, including DigiEver DS-2105 Pro.

“Further investigation into this campaign revealed a new botnet that calls itself the “Hail Cock Botnet” that’s been active since at least September 2024.” reads the analysis published by Akamai. “Using a Mirai malware variant that incorporates ChaCha20 and XOR decryption algorithms, it has been seen compromising vulnerable Internet of Things (IoT) devices in the wild, such as the DigiEver DVR, and TP-Link devices through CVE-2023-1389.”

Upon exploiting the vulnerability, the malicious code can inject commands via the ntp parameter, allowing attackers to download Mirai-based malware through HTTP POST requests over port 80, referencing “IP Address:80/cfg_system_time.htm” in the HTTP Referer header.

The new Mirai malware variant also targets the TP-Link flaw CVE-2023-1389 and the vulnerability CVE-2018-17532 affecting Teltonika RUT9XX routers.

The malware maintains persistence using a cron job that downloads a shell script from “hailcocks[.]ru.”

The bot uses curl or wget to download the “wget.sh” file, ensuring compatibility if one is unavailable on the host.

The malware connects to various hosts for Telnet/SSH brute-forcing and uses a single IP linked to “kingstonwikkerink[.]dyn” for C2 communication. Compromised hosts display unique strings during execution, including “you are now apart of hail cock botnet” in older versions and “I just wanna look after my cats, man.” in newer ones.

“One of the easiest methods for threat actors to compromise new hosts is to target outdated firmware or retired hardware.” concludes the report. “The DigiEver DS-2105 Pro, which is approximately 10 years old now, is an example. Hardware manufacturers do not always issue patches for retired devices, and the manufacturer itself may sometimes be defunct. Therefore, in circumstances in which security patches are unavailable and unlikely to come, we recommend upgrading vulnerable devices to a newer model.”

Akamai’s report includes indicators of compromise (IoC) associated with these attacks along with Yara rules for the detection of the threat.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:42 am, Juni 23, 2025
Wetter-Symbol 18°C
L: 17° | H: 19°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 76 %
Druck: 1011 mb
Wind: 15 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 19°°C 0.2 mm 20% 14 mph 78 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 24°°C 0.2 mm 20% 14 mph 81 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 11 mph 88 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 25°°C 1 mm 100% 15 mph 84 % 1018 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
15° | 28°°C 0 mm 0% 15 mph 70 % 1020 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
17° | 18°°C 0.2 mm 20% 13 mph 78 % 1011 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
16° | 16°°C 0.2 mm 20% 13 mph 72 % 1012 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 12 mph 43 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 12 mph 34 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 32 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 13 mph 39 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 11 mph 55 % 1016 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 9 mph 68 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€87,752.27
-2.04%
Ethereum(ETH)
€1,945.61
-2.82%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.76
-2.99%
Solana(SOL)
€115.27
-3.15%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.132089
-2.91%
Shiba Inu(SHIB)
€0.000010
-3.38%
Pepe(PEPE)
€0.000008
-5.45%
Peanut das Eichhörnchen(PNUT)
€0.218896
13.10%
Nach oben scrollen