New botnet exploits vulnerabilities in NVRs, TP-Link routers

Share:

A new Mirai-based botnetis actively exploiting a remote code execution vulnerability that has not received a tracker number and appears to be unpatched in DigiEver DS-2105 Pro NVRs.

The campaign started in October and targets multiple network video recorders and TP-Link routers with outdated firmware.

One of the vulnerabilities used in the campaign was documented by TXOne researcher Ta-Lun Yen and presented last year at the DefCamp security conference in Bucharest, Romania. The researcher said at the time that the issue affects multiple DVR devices.

Akamai researchers observed that the botnet started to exploit the flaw in mid-November, but found evidence that the campaign has been active since at least September.

Apart from the DigiEver flaw, the new Mirai malware variant also targets CVE-2023-1389 on TP-Link devices and CVE-2018-17532 on Teltonika RUT9XX routers.

Attacks on DigiEver NVRs

The vulnerability exploited to compromise DigiEver NVRs is a remote code execution (RCE) flaw and the hackers are targeting the ‘/cgi-bin/cgi_main. cgi’ URI, which improperly validates user inputs.

This allows remote unauthenticated attackers to inject commands like ‘curl’ and ‘chmod’ via certain parameters, such as the ntp field in HTTP POST requests.

Akamai says that the attacks it has seen by this Mirai-based botnet appear similar to what is described in Ta-Lun Yen’s presentation.

Through command injection, the attackers fetch the malware binary from an external server and enlist the device into its botnet. Persistence is achieved by adding cron jobs.

Once the device is compromised, it is then used to conduct distributed denial of service (DDoS) attacks or to spread to other devices by leveraging exploit sets and credential lists.

Akamai says the new Mirai variant is notable for its use of XOR and ChaCha20 encryption and its targeting of a broad range of system architectures, including x86, ARM, and MIPS.

“Although employing complex decryption methods isn’t new, it suggests evolving tactics, techniques, and procedures among Mirai-based botnet operators,” comments Akamai.

“This is mostly notable because many Mirai-based botnets still depend on the original string obfuscation logic from recycled code that was included in the original Mirai malware source code release,” the researchers say.

The researchers note that the botnet also exploits CVE-2018-17532, a vulnerability in Teltonika RUT9XX routers as well as CVE-2023-1389, which impacts TP-Link devices.

Indicators of compromise (IoC) associated with the campaign are available at the end of Akamai’s report, along with Yara rules for detecting and blocking the threat.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:52 pm, Apr 22, 2025
weather icon 10°C
L: 9° | H: 11°
broken clouds
Humidity: 80 %
Pressure: 1015 mb
Wind: 8 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 77%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:49 am
Sunset: 8:07 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
9° | 11°°C 1 mm 100% 13 mph 93 % 1018 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
7° | 16°°C 0.2 mm 20% 6 mph 85 % 1023 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
8° | 17°°C 0 mm 0% 9 mph 84 % 1024 mb 0 mm/h
Sat Apr 26 10:00 pm
weather icon
9° | 16°°C 0.99 mm 99% 6 mph 89 % 1024 mb 0 mm/h
Sun Apr 27 10:00 pm
weather icon
9° | 19°°C 0 mm 0% 8 mph 96 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
10° | 10°°C 0 mm 0% 7 mph 79 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
8° | 9°°C 1 mm 100% 9 mph 90 % 1012 mb 0 mm/h
Tomorrow 7:00 am
weather icon
8° | 8°°C 1 mm 100% 13 mph 93 % 1009 mb 0 mm/h
Tomorrow 10:00 am
weather icon
10° | 10°°C 1 mm 100% 10 mph 93 % 1010 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
11° | 11°°C 0.8 mm 80% 9 mph 84 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
11° | 11°°C 0.2 mm 20% 11 mph 72 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
11° | 11°°C 0 mm 0% 7 mph 73 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
9° | 9°°C 0 mm 0% 3 mph 89 % 1018 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€79,591.07
4.83%
Ethereum(ETH)
€1,501.64
9.40%
Tether(USDT)
€0.87
0.03%
XRP(XRP)
€1.90
4.89%
Solana(SOL)
€126.80
6.67%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.152318
10.45%
Shiba Inu(SHIB)
€0.000011
8.55%
Pepe(PEPE)
€0.000008
10.86%
Scroll to Top