DigiEver IoT Devices Exploited To Deliver Mirai-based Malware

Share:

A new Mirai-based botnet, “Hail Cock Botnet,” has been exploiting vulnerable IoT devices, including DigiEver DVRs and TP-Link devices with CVE-2023-1389.

The botnet, active since September 2024, leverages a variant of Mirai malware with enhanced encryption.

A recent uptick in attacks targeting the URI /cgi-bin/cgi_main.cgi, exploiting an RCE vulnerability in DigiEver DS-2105 Pro devices, aligns with this campaign. While the vulnerability lacks a CVE, it was previously disclosed by Ta-Lun Yen of TXOne Research.

The researcher identified vulnerable DigiEver DVRs exposed online and by analyzing the firmware, they discovered the `/cgi-bin/cgi_main.cgi` endpoint.

Exploiting this endpoint, they successfully executed arbitrary code on the vulnerable devices, potentially enabling remote control or data theft.

<img class="i-amphtml-intrinsic-sizer" style="box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;" role="presentation" src="data:;base64,” alt=”” aria-hidden=”true” />
Endpoint with suspected vulnerability

It was discovered targeting devices with known vulnerabilities and exploiting command injection flaws in DigiEver routers (/cfg_system_time.htm ntp parameter), TP-Link routers (/cgi-bin/luci;stok=/locale endpoint), and Tenda HG6 routers (/boaform/admin/formTracert).

2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide

The botnet injects commands to download malicious scripts from remote servers, which then fetch and execute Mirai-based malware, where the attackers also target other vulnerabilities like CVE-2018-17532 using similar techniques.

<img class="i-amphtml-intrinsic-sizer" style="box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;" role="presentation" src="data:;base64,” alt=”” aria-hidden=”true” />Contents of the “b.sh” shell script
Contents of the “b.sh” shell script

The Mirai-based malware samples analyzed employed a sophisticated multi-layer encryption scheme, combining XOR and ChaCha20 algorithms, which, while not entirely novel, demonstrates a clear evolution in the tactics of botnet operators.

It’s ability to decrypt critical strings, such as botnet affiliation messages and default device credentials, highlights the increasing complexity of these threats and by leveraging advanced cryptographic methods, the malware aims to evade detection and hinder analysis efforts, thereby expanding its reach and impact.

<img class="i-amphtml-intrinsic-sizer" style="box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;" role="presentation" src="data:;base64,” alt=”” aria-hidden=”true” />
Decrypting with Salsa20 and ChaCha20

Akamai analyzed malware samples in a sandbox environment and observed persistence mechanisms, where the malware creates a cron job to download a shell script named “wget.sh” from “hailcocks.ru” and executes it, which likely establishes communication with the botnet’s C2 server at “kingstonwikkerink.dyn.”

The malware also leaves a fingerprint in the console, with older versions announcing its affiliation to “hail cock botnet” and newer ones displaying a seemingly harmless message, “I just wanna look after my cats, man.”.

<img class="i-amphtml-intrinsic-sizer" style="box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;" role="presentation" src="data:;base64,” alt=”” aria-hidden=”true” />Newer malware console output message

As evidenced by the recent operation of the Hail Cock botnet, cybercriminals create botnets by utilizing obsolete hardware and firmware, where devices like the 10-year-old DigiEver DS-2105 Pro, lacking manufacturer support for security patches, are prime targets.

To mitigate risks, users should upgrade vulnerable devices to newer, more secure models, especially when manufacturers cease providing updates.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
6:10 am, May 19, 2025
weather icon 10°C
L: 9° | H: 11°
overcast clouds
Humidity: 85 %
Pressure: 1020 mb
Wind: 5 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:02 am
Sunset: 8:51 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
9° | 11°°C 0 mm 0% 11 mph 85 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 21°°C 0 mm 0% 9 mph 69 % 1022 mb 0 mm/h
Wed May 21 10:00 pm
weather icon
14° | 22°°C 0 mm 0% 12 mph 63 % 1020 mb 0 mm/h
Thu May 22 10:00 pm
weather icon
11° | 18°°C 0 mm 0% 12 mph 64 % 1023 mb 0 mm/h
Fri May 23 10:00 pm
weather icon
7° | 19°°C 0 mm 0% 9 mph 69 % 1024 mb 0 mm/h
Today 7:00 am
weather icon
10° | 10°°C 0 mm 0% 6 mph 85 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
12° | 15°°C 0 mm 0% 7 mph 76 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
16° | 19°°C 0 mm 0% 9 mph 54 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
19° | 19°°C 0 mm 0% 11 mph 40 % 1019 mb 0 mm/h
Today 7:00 pm
weather icon
17° | 17°°C 0 mm 0% 9 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 6 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 11°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 10°°C 0 mm 0% 5 mph 69 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,124.18
-0.26%
Ethereum(ETH)
€2,118.63
-4.64%
Tether(USDT)
€0.89
-0.01%
XRP(XRP)
€2.09
-0.98%
Solana(SOL)
€146.93
-2.25%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.195074
0.79%
Shiba Inu(SHIB)
€0.000013
-0.63%
Pepe(PEPE)
€0.000012
4.08%
Peanut the Squirrel(PNUT)
€0.281390
3.27%
Scroll to Top