Juniper warns of Mirai botnet scanning for Session Smart routers

Share:

Juniper Networks has warned customers of Mirai malware attacks scanning the Internet for Session Smart routers using default credentials.

As the networking infrastructure company explained, the malware scans for devices with default login credentials and executes commands remotely after gaining access, enabling a wide range of malicious activities.

The campaign was first observed on December 11, when the first infected routers were found on customers’ networks. Later, the operators of this Mirai-based botnet used the compromised devices to launch distributed denial-of-service (DDoS) attacks.

“On Wednesday, December 11, 2024, several customers reported suspicious behavior on their Session Smart Network (SSN) platforms,” says a security advisory published this Tuesday.

“Any customer not following recommended best practices and still using default passwords can be considered compromised as the default SSR passwords have been added to the virus database.”

Juniper also shared indicators of compromise admins should look for on their networks and devices to detect potential Mirai malware activity, including:

  • scans for devices on common Layer 4 ports (e.g., 23, 2323, 80, 8080),
  • failed login attempts on SSH services indicative of brute-force attacks,
  • sudden spike in outbound traffic volume hinting at devices being co-opted in DDoS attacks,
  • devices rebooting or behaving erratically, suggesting they’ve been compromised,
  • SSH connections from known malicious IP addresses.

The company advised customers to immediately ensure their devices follow recommended username and password policies, including changing the default credentials on all Session Smart routers and using unique and strong passwords across all devices.

Admins are also recommended to keep firmware updated, review access logs for anomalies, set alerts automatically triggered when suspicious activity is detected, deploy intrusion detection systems to monitor network activity, and use firewalls to block unauthorized access to Internet-exposed devices.

Juniper also warned that routers already infected in these attacks must be reimaged before being brought back online.

“If a system is found to be infected, the only certain way of stopping the threat is by reimaging the system as it cannot be determined exactly what might have been changed or obtained from the device,” Juniper said.

Last year, in August, the ShadowServer threat monitoring service warned of ongoing attacks targeting a critical remote code execution exploit chain impacting Juniper EX switches and SRX firewalls using a watchTowr Labs proof-of-concept (PoC) exploit.

Since then, Juniper also warned of a critical RCE bug in its firewalls and switches in January and released an out-of-cycle patch for a maximum-severity authentication bypass flaw in its Session Smart Router (SSR), Session Smart Conductor, and WAN Assurance Router products.

Update December 20, 03:17 EST: Revised article and title to describe the attacks as scanning activity.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:18 pm, Feb 8, 2025
weather icon 5°C
L: 4° | H: 6°
overcast clouds
Humidity: 92 %
Pressure: 1018 mb
Wind: 10 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 2 km
Sunrise: 7:27 am
Sunset: 5:02 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
4° | 6°°C 0.2 mm 20% 6 mph 93 % 1023 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 7°°C 1 mm 100% 10 mph 97 % 1031 mb 0 mm/h
Mon Feb 10 9:00 pm
weather icon
3° | 5°°C 0.2 mm 20% 11 mph 95 % 1031 mb 0 mm/h
Tue Feb 11 9:00 pm
weather icon
3° | 7°°C 1 mm 100% 6 mph 98 % 1022 mb 0 mm/h
Wed Feb 12 9:00 pm
weather icon
4° | 9°°C 0 mm 0% 10 mph 97 % 1027 mb 0 mm/h
Today 3:00 pm
weather icon
5° | 6°°C 0.2 mm 20% 6 mph 93 % 1018 mb 0 mm/h
Today 6:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 82 % 1020 mb 0 mm/h
Today 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 4 mph 81 % 1023 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 3°°C 0 mm 0% 5 mph 87 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 6 mph 87 % 1025 mb 0 mm/h
Tomorrow 6:00 am
weather icon
4° | 4°°C 0.89 mm 89% 8 mph 97 % 1026 mb 0 mm/h
Tomorrow 9:00 am
weather icon
4° | 4°°C 1 mm 100% 9 mph 96 % 1028 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 1 mm 100% 10 mph 88 % 1029 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,081.62
-1.54%
Ethereum(ETH)
€2,530.67
-5.09%
Tether(USDT)
€0.97
-0.04%
XRP(XRP)
€2.33
0.06%
Solana(SOL)
€187.79
-1.97%
USDC(USDC)
€0.97
0.01%
Dogecoin(DOGE)
€0.240031
-2.47%
Shiba Inu(SHIB)
€0.000015
2.96%
Pepe(PEPE)
€0.000009
-3.03%
Scroll to Top