Threat Advisory

InfectedSlurs Botnet Spreads Mirai via Zero-Days in Routers and NVRs

Threat: Vulnerability/Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researcher has discovered two zero-day vulnerabilities with remote code execution (RCE) capabilities exploited in real-world scenarios. These vulnerabilities, reported to vendors awaiting patch releases in December 2023, are currently utilized to orchestrate a distributed denial-of-service (DDoS) botnet. The ongoing campaign monitored through custom-built honeypots, employs the Mirai malware family to target routers and network video recorder (NVR) devices using default admin credentials, thereby installing Mirai variants upon successful infiltration.[/subscribe_to_unlock_form]

Summary:

Researcher has discovered two zero-day vulnerabilities with remote code execution (RCE) capabilities exploited in real-world scenarios. These vulnerabilities, reported to vendors awaiting patch releases in December 2023, are currently utilized to orchestrate a distributed denial-of-service (DDoS) botnet. The ongoing campaign monitored through custom-built honeypots, employs the Mirai malware family to target routers and network video recorder (NVR) devices using default admin credentials, thereby installing Mirai variants upon successful infiltration.[emaillocker id="1283"]

Through meticulous analysis, specific HTTP exploit paths and targeted ports were unveiled, leading to the identification of devices hosting peculiar HTTP response headers. These devices, initially perceived as potential honeypots or pranks due to slang-rooted names and versions, eventually revealed themselves as potentially vulnerable devices. By decrypting username and password values from exploit payloads, Akamai identified these attacks as targeting unidentified devices associated with real-time streaming protocol (RTSP) support, hinting at CCTV/NVR/DVR/security camera devices. Further examination using manuals and documentation of specific NVR offerings pinpointed default administrative credentials, exposing these devices to a new zero-day exploit. A second zero-day exploit affecting outlet-based wireless LAN routers for hotels and residences was also identified. However, details regarding impacted device models and versions remain forthcoming, making it challenging to precisely discern affected devices.

The active exploitation of undisclosed vulnerabilities in the wild prompted Akamai to caution the cybersecurity community. The blog refrains from divulging vendor names to allow for responsible disclosure, patching, and remediation. The Mirai-based botnet, named InfectedSlurs, spawned from this exploit campaign. Researchers noted distinctive characteristics in its command and control (C2) infrastructure, revealing racial epithets and offensive language in domain naming conventions, mirroring JenX and hailBot Mirai variants. Although certain C2 domains align with specific IP blocks, limited resolutions suggest a controlled domain structure. Mitigation strategies advised by researchers include checking default credentials on IoT devices, isolation, and investigation of vulnerable devices, and implementing recommended measures against DDoS attacks outlined by researchers.

Recommendations:

  • As with any threat, swift mitigation is of the utmost importance. Here are some tips to remain safe against InfectedSlurs and other similar botnets.

InfectedSlur infections

  • First and foremost, check for default credentials on IoT devices and change them if they exist.
  • If you find devices believed to be vulnerable in your environments, isolate them if possible and investigate for potential compromise.

DDoS attacks

  • Conduct a thorough examination of critical subnets and IP spaces to confirm the presence of effective mitigation controls.
  • Configure proactive security controls through a network cloud firewall. This external firewall serves as a potent, easily deployable, and user-friendly tool to efficiently block undesired traffic globally and centrally, safeguarding your networks and specific targets within your networks.

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2023/11/mirai-based-botnet-exploiting-zero-day.html

[/emaillocker]
crossmenu