Summary:
Researcher has discovered two zero-day vulnerabilities with remote code execution (RCE) capabilities exploited in real-world scenarios. These vulnerabilities, reported to vendors awaiting patch releases in December 2023, are currently utilized to orchestrate a distributed denial-of-service (DDoS) botnet. The ongoing campaign monitored through custom-built honeypots, employs the Mirai malware family to target routers and network video recorder (NVR) devices using default admin credentials, thereby installing Mirai variants upon successful infiltration.[/subscribe_to_unlock_form]
Summary:
Researcher has discovered two zero-day vulnerabilities with remote code execution (RCE) capabilities exploited in real-world scenarios. These vulnerabilities, reported to vendors awaiting patch releases in December 2023, are currently utilized to orchestrate a distributed denial-of-service (DDoS) botnet. The ongoing campaign monitored through custom-built honeypots, employs the Mirai malware family to target routers and network video recorder (NVR) devices using default admin credentials, thereby installing Mirai variants upon successful infiltration.[emaillocker id="1283"]
Through meticulous analysis, specific HTTP exploit paths and targeted ports were unveiled, leading to the identification of devices hosting peculiar HTTP response headers. These devices, initially perceived as potential honeypots or pranks due to slang-rooted names and versions, eventually revealed themselves as potentially vulnerable devices. By decrypting username and password values from exploit payloads, Akamai identified these attacks as targeting unidentified devices associated with real-time streaming protocol (RTSP) support, hinting at CCTV/NVR/DVR/security camera devices. Further examination using manuals and documentation of specific NVR offerings pinpointed default administrative credentials, exposing these devices to a new zero-day exploit. A second zero-day exploit affecting outlet-based wireless LAN routers for hotels and residences was also identified. However, details regarding impacted device models and versions remain forthcoming, making it challenging to precisely discern affected devices.
The active exploitation of undisclosed vulnerabilities in the wild prompted Akamai to caution the cybersecurity community. The blog refrains from divulging vendor names to allow for responsible disclosure, patching, and remediation. The Mirai-based botnet, named InfectedSlurs, spawned from this exploit campaign. Researchers noted distinctive characteristics in its command and control (C2) infrastructure, revealing racial epithets and offensive language in domain naming conventions, mirroring JenX and hailBot Mirai variants. Although certain C2 domains align with specific IP blocks, limited resolutions suggest a controlled domain structure. Mitigation strategies advised by researchers include checking default credentials on IoT devices, isolation, and investigation of vulnerable devices, and implementing recommended measures against DDoS attacks outlined by researchers.
Recommendations:
InfectedSlur infections
DDoS attacks
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/11/mirai-based-botnet-exploiting-zero-day.html
[/emaillocker]