Threat Advisory

Corona Mirai Botnet Exploits AVTECH IP Cameras via Zero-Day Vulnerabilities

Threat: Vulnerability/Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A newly discovered command injection vulnerability in AVTECH IP camera devices allows for remote code execution (RCE) and is being actively exploited in the wild. This vulnerability, found in the brightness function of the devices, has become a focal point for a botnet campaign spreading a variant of the Mirai malware. This botnet leverages both the new vulnerability and several older, unpatched vulnerabilities to infect and control target systems.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A newly discovered command injection vulnerability in AVTECH IP camera devices allows for remote code execution (RCE) and is being actively exploited in the wild. This vulnerability, found in the brightness function of the devices, has become a focal point for a botnet campaign spreading a variant of the Mirai malware. This botnet leverages both the new vulnerability and several older, unpatched vulnerabilities to infect and control target systems.[emaillocker id="1283"]

 

The zero-day vulnerability, identified as CVE-2024-7029, is a command injection flaw within the brightness function of AVTECH CCTV cameras. This vulnerability enables remote code execution (RCE) through the injection of malicious commands. The affected devices are those running specific AVTECH firmware versions. Despite the discontinuation of these models, they are still in use globally, particularly within critical infrastructure. Exploiting this vulnerability allows attackers to execute commands with elevated privileges, facilitating the spread of the Mirai variant. The botnet campaign also targets other known vulnerabilities, including a Hadoop YARN RCE, CVE-2014-8361, and CVE-2017-17215. These older vulnerabilities remain unpatched in many systems, enabling their ongoing exploitation by the botnet.

 

This botnet campaign highlights the growing trend of exploiting both new and under-the-radar vulnerabilities in legacy systems, posing significant risks to organizations that rely on outdated hardware and software. Given the lack of patches for some of these vulnerabilities, organizations should prioritize patch management where possible and consider decommissioning vulnerable devices to mitigate security risks. The campaign underscores the importance of proactive threat monitoring and timely vulnerability management in safeguarding critical infrastructure.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access T1190 Exploit Public-Facing Application
Execution  T1059 Command and Scripting Interpreter
T1203 Exploitation for Client Execution
Defense Evasion  T1078 Valid Accounts
T1027 Obfuscated Files or Information
Collection T1074 Data Staged
Command and Control T1071 Application Layer Protocol
Impact T1498 Network Denial of Service

RECOMMENDATION:

  • The AVTECH AVM1203 device has been discontinued and no longer receives firmware updates. To mitigate this vulnerability, we recommend upgrading to a newer model that continues to receive security updates.

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/malware-exploits-5-year-old-zero-day-to-infect-end-of-life-ip-cameras/

[/emaillocker]
crossmenu