router-ddos

Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks

Teilen:

A Mirai botnet variant has been found exploiting a newly disclosed security flaw impacting Four-Faith industrial routers since early November 2024 with the goal of conducting distributed denial-of-service (DDoS) attacks.

The botnet maintains approximately 15,000 daily active IP addresses, with the infections primarily scattered across China, Iran, Russia, Turkey, and the United States.

Exploiting an arsenal of over 20 known security vulnerabilities and weak Telnet credentials for initial access, the malware is known to have been active since February 2024. The botnet has been dubbed “gayfemboy” in reference to the offensive term present in the source code.

QiAnXin XLab said it observed the malware leveraging a zero-day vulnerability in industrial routers manufactured by China-based Four-Faith to deliver the artifacts as early as November 9, 2024.

The vulnerability in question is CVE-2024-12856 (CVSS score: 7.2), which refers to an operating system (OS) command injection bug affecting router models F3x24 and F3x36 by taking advantage of unchanged default credentials.

Late last month, VulnCheck told The Hacker News that the vulnerability has been exploited in the wild to drop reverse shells and a Mirai-like payload on compromised devices.

Some of the other security flaws exploited by the botnet to extend its reach and scale include CVE-2013-3307, CVE-2013-7471, CVE-2014-8361, CVE-2016-20016, CVE-2017-17215, CVE-2017-5259, CVE-2020-25499, CVE-2020-9054, CVE-2021-35394, CVE-2023-26801, CVE-2024-8956, and CVE-2024-8957.

Once launched, the malware attempts to hide malicious processes and implements a Mirai-based command format to scan for vulnerable devices, update itself, and launch DDoS attacks against targets of interest.

DDoS attacks leveraging the botnet have targeted hundreds of different entities on a daily basis, with the activity scaling a new peak in October and November 2024. The attacks, while lasting between 10 and 30 seconds, generate traffic around 100 Gbps.

The disclosure comes weeks after Juniper Networks warned that Session Smart Router (SSR) products with default passwords are being targeted by malicious actors to drop the Mirai botnet malware. Akamai has also revealed Mirai malware infections that weaponize a remote code execution flaw in DigiEver DVRs.

“DDoS has become one of the most common and destructive forms of cyber attacks,” XLab researchers said. “Its attack modes are diverse, attack paths are highly concealed, and it can employ continuously evolving strategies and techniques to conduct precise strikes against various industries and systems, posing a significant threat to enterprises, government organizations, and individual users.”

The development also comes as threat actors are leveraging susceptible and misconfigured PHP servers (e.g., CVE-2024-4577) to deploy a cryptocurrency miner called PacketCrypt.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:33 am, Juni 6, 2025
Wetter-Symbol 11°C
L: 10° | H: 12°
klarer Himmel
Luftfeuchtigkeit: 88 %
Druck: 1004 mb
Wind: 12 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 9%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:12 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
10° | 12°°C 1 mm 100% 14 mph 88 % 1009 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 16°°C 1 mm 100% 14 mph 96 % 1009 mb 0 mm/h
So. Juni 08 10:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 12 mph 88 % 1023 mb 0 mm/h
Mo. Juni 09 10:00 pm
Wetter-Symbol
10° | 20°°C 0 mm 0% 10 mph 89 % 1025 mb 0 mm/h
Di. Juni 10 10:00 pm
Wetter-Symbol
12° | 21°°C 0.6 mm 60% 10 mph 85 % 1023 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 9 mph 88 % 1004 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 9 mph 87 % 1005 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
15° | 17°°C 0 mm 0% 12 mph 72 % 1006 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 20°°C 1 mm 100% 11 mph 67 % 1008 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
20° | 20°°C 0.29 mm 29% 14 mph 33 % 1008 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 46 % 1009 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 4 mph 65 % 1009 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 75 % 1008 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,796.93
-3.11%
Ethereum(ETH)
€2,110.47
-7.54%
Fesseln(USDT)
€0.87
-0.02%
XRP(XRP)
€1.83
-4.66%
Solana(SOL)
€127.03
-5.33%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.149469
-9.44%
Shiba Inu(SHIB)
€0.000010
-6.44%
Pepe(PEPE)
€0.000010
-10.37%
Peanut das Eichhörnchen(PNUT)
€0.233638
-5.20%
Nach oben scrollen