New botnet exploits vulnerabilities in NVRs, TP-Link routers

Share:

A new Mirai-based botnetis actively exploiting a remote code execution vulnerability that has not received a tracker number and appears to be unpatched in DigiEver DS-2105 Pro NVRs.

The campaign started in October and targets multiple network video recorders and TP-Link routers with outdated firmware.

One of the vulnerabilities used in the campaign was documented by TXOne researcher Ta-Lun Yen and presented last year at the DefCamp security conference in Bucharest, Romania. The researcher said at the time that the issue affects multiple DVR devices.

Akamai researchers observed that the botnet started to exploit the flaw in mid-November, but found evidence that the campaign has been active since at least September.

Apart from the DigiEver flaw, the new Mirai malware variant also targets CVE-2023-1389 on TP-Link devices and CVE-2018-17532 on Teltonika RUT9XX routers.

Attacks on DigiEver NVRs

The vulnerability exploited to compromise DigiEver NVRs is a remote code execution (RCE) flaw and the hackers are targeting the ‘/cgi-bin/cgi_main. cgi’ URI, which improperly validates user inputs.

This allows remote unauthenticated attackers to inject commands like ‘curl’ and ‘chmod’ via certain parameters, such as the ntp field in HTTP POST requests.

Akamai says that the attacks it has seen by this Mirai-based botnet appear similar to what is described in Ta-Lun Yen’s presentation.

Through command injection, the attackers fetch the malware binary from an external server and enlist the device into its botnet. Persistence is achieved by adding cron jobs.

Once the device is compromised, it is then used to conduct distributed denial of service (DDoS) attacks or to spread to other devices by leveraging exploit sets and credential lists.

Akamai says the new Mirai variant is notable for its use of XOR and ChaCha20 encryption and its targeting of a broad range of system architectures, including x86, ARM, and MIPS.

“Although employing complex decryption methods isn’t new, it suggests evolving tactics, techniques, and procedures among Mirai-based botnet operators,” comments Akamai.

“This is mostly notable because many Mirai-based botnets still depend on the original string obfuscation logic from recycled code that was included in the original Mirai malware source code release,” the researchers say.

The researchers note that the botnet also exploits CVE-2018-17532, a vulnerability in Teltonika RUT9XX routers as well as CVE-2023-1389, which impacts TP-Link devices.

Indicators of compromise (IoC) associated with the campaign are available at the end of Akamai’s report, along with Yara rules for detecting and blocking the threat.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:07 pm, Jan 16, 2025
weather icon 7°C
L: 7° | H: 8°
overcast clouds
Humidity: 85 %
Pressure: 1035 mb
Wind: 5 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:58 am
Sunset: 4:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
7° | 8°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 4 mph 83 % 1034 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 7 mph 88 % 1023 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 7 mph 93 % 1021 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 3 mph 96 % 1021 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 6°°C 0 mm 0% 3 mph 89 % 1035 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 5°°C 0 mm 0% 4 mph 93 % 1034 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 96 % 1035 mb 0 mm/h
Tomorrow 9:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 95 % 1035 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
7° | 7°°C 0 mm 0% 5 mph 77 % 1035 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 3 mph 76 % 1034 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
5° | 5°°C 0 mm 0% 3 mph 88 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 3 mph 86 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,177.81
0.34%
Ethereum(ETH)
€3,223.90
-3.40%
XRP(XRP)
€3.20
8.30%
Tether(USDT)
€0.97
-0.03%
Solana(SOL)
€205.85
4.36%
Dogecoin(DOGE)
€0.369915
0.97%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000021
-0.58%
Pepe(PEPE)
€0.000017
-2.11%
Peanut the Squirrel(PNUT)
€0.59
-4.85%
Scroll to Top