EXECUTIVE SUMMARY:
The AIRASHI botnet exploits various vulnerabilities to spread and carry out attacks. These include weaknesses in AMTK Camera cmd.cgi, Google Android ADB Debug Server, AVTECH IP Camera devices, and several CVEs like CVE-2013-3307, CVE-2016-20016, and CVE-2020-25499. The botnet also targets specific systems like cnPilot, OptiLink ONT1GEW, and Shenzhen TVT Digital Technology Co. Ltd. devices, using methods like remote code execution to infect devices.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
The AIRASHI botnet exploits various vulnerabilities to spread and carry out attacks. These include weaknesses in AMTK Camera cmd.cgi, Google Android ADB Debug Server, AVTECH IP Camera devices, and several CVEs like CVE-2013-3307, CVE-2016-20016, and CVE-2020-25499. The botnet also targets specific systems like cnPilot, OptiLink ONT1GEW, and Shenzhen TVT Digital Technology Co. Ltd. devices, using methods like remote code execution to infect devices.[emaillocker id="1283"]
Technically, AIRASHI uses advanced methods for evading detection and maintaining control over infected systems. The botnet employs encryption techniques and utilizes various flaws such as the Gargoyle Route run_commands.sh and the LILIN DVR vulnerabilities to enable remote payload execution. These flaws allow AIRASHI to exploit devices worldwide, making it a persistent threat. The malware continuously updates itself, improving its capabilities.
In conclusion, AIRASHI illustrates the growing complexity of botnets, which use a wide range of vulnerabilities to spread and maintain control over infected devices. The botnet’s ability to exploit remote code execution flaws in consumer hardware, including cameras and routers, underscores the need for stronger security measures. With numerous CVEs and vulnerabilities still in play, defending against AIRASHI will require consistent patching and monitoring of affected devices.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1071 | Application Layer Protocol |
| Execution | T1203 | Exploitation for Client Execution |
| Execution | T1106 | Native API |
| Persistence | T1136 | Create Account |
| Defense Evasion | T1070 | Indicator Removal |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2025/01/hackers-exploit-zero-day-in-cnpilot.html