CVE-2014-8361
published 2015-05-01CVE-2014-8361: The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-09
Exploited in the wild
EPSS
99.98%
100.0th percentile
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aterm | w1200ex-ms_firmware | <= 1.3.1 | — |
| aterm | w1200ex_firmware | <= 1.3.1 | — |
| aterm | wg1200hp2_firmware | <= 2.5.0 | — |
| aterm | wg1200hp3_firmware | <= 1.3.1 | — |
| aterm | wg1200hs2_firmware | <= 2.5.0 | — |
| aterm | wg1800hp3_firmware | <= 1.5.1 | — |
| aterm | wg1800hp4_firmware | <= 1.3.1 | — |
| aterm | wg1900hp2_firmware | <= 1.3.1 | — |
| aterm | wg1900hp_firmware | <= 2.5.1 | — |
| dlink | dir-501_firmware | <= 1.01b04 | — |
| dlink | dir-515_firmware | <= 1.01b04 | — |
| dlink | dir-600l_firmware | <= 1.15 | — |
| dlink | dir-600l_firmware | <= 2.056b06 | — |
| dlink | dir-605l_firmware | <= 1.14b06 | — |
| dlink | dir-605l_firmware | <= 2.07b02 | — |
| dlink | dir-605l_firmware | <= 3.03b07 | — |
| dlink | dir-615_firmware | <= 6.06b03 | — |
| dlink | dir-615_firmware | — | — |
| dlink | dir-619l_firmware | <= 1.15 | — |
| dlink | dir-619l_firmware | <= 2.07b02 | — |
| dlink | dir-809_firmware | <= 1.04b02 | — |
| dlink | dir-900l_firmware | < 1.15b01 | 1.15b01 |
| dlink | dir-905l_firmware | <= 2.05b01 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2014-8361 exploits the miniigd UPnP SOAP service via HTTP POST to the WANIPConnection:1 service using the AddPortMapping action; the NewInternalClient parameter is used for OS command injection via backtick characters. Monitor for SOAP POST requests containing shell metacharacters (backticks) in the NewInternalClient field. ↗
- →Scan for inbound TCP traffic on port 52869, which is the port used by the Realtek miniigd UPnP SOAP service targeted by CVE-2014-8361. Elevated scanning activity on this port is a strong indicator of exploitation attempts. ↗
- →Yowai (Mirai variant) listens on port 6 for C2 commands. Detect outbound connections from IoT devices to port 6 as a potential indicator of Yowai infection. ↗
- →Detect HTTP requests with User-Agent 'Hito/2.0' as an indicator of the Mirai variant hosted at 178.62.227.13 exploiting CVE-2014-8361 and other vulnerabilities. ↗
- →The new Mirai variant (Unit 42, Feb 2019) uses a modified XOR obfuscation with 10 8-byte keys cumulatively XOR-ed, effectively equivalent to a byte-wise XOR with 0x5A. Use this as a config-table decryption signature when triaging samples. ↗
- →Trend Micro IDS/IPS rule 1134286 covers CVE-2014-8361 (WEB Realtek SDK Miniigd UPnP SOAP Command Execution). Use this signature ID as a reference for detection tuning. ↗
- ·The Okiru/Satori CVE-2014-8361 exploit contains a typo in the requested URI (should be /picsdesc.xml), causing the SOAP request to fail with HTTP 404. The exploit was assessed as non-functional at the time of analysis, generating only background noise rather than successful compromises. ↗
- ·As of the Fortinet analysis (Dec 2017), at least 13,000 devices were potentially still vulnerable to CVE-2014-8361 based on Shodan results for port 52869, with Taiwan (33%), Ukraine (17%), and Japan (14%) as the top affected countries. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Realtek SDK Improper Input Validation Vulnerability
cisa·2023-09-18·CVSS 9.8
CVE-2014-8361 [CRITICAL] CWE-20 Realtek SDK Improper Input Validation Vulnerability
Vulnerability: Realtek SDK Improper Input Validation Vulnerability
Affected: Realtek SDK
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://web.archive.org/web/20150831100501/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055; https://nvd.nist.gov/vuln/detail/CVE-2014-8361
Remediation Due Date: 2023-10-09
GHSA
GHSA-r272-2vh9-q99x: The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request
ghsa_unreviewed·2022-05-13
CVE-2014-8361 [HIGH] CWE-20 GHSA-r272-2vh9-q99x: The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request.
VulnCheck
Realtek SDK Improper Input Validation Vulnerability
vulncheck·2014·CVSS 9.8
CVE-2014-8361 [CRITICAL] CWE-20 Realtek SDK Improper Input Validation Vulnerability
Realtek SDK Improper Input Validation Vulnerability
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.
Affected: Realtek SDK
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2014-8361; https://blog.netlab.360.com/art-of-steal-satori-variant-is-robbing-eth-bitcoin-by-replacing-wallet-address-en/; https://blog.newskysecurity.com/masuta-satori-creators-second-botnet-weaponizes-a-new-router-exploit-2ddc51cc52a7; https://unit42.paloaltonetworks.com/unit42-finds-new-mirai-gafgyt-iotlinux-botnet-campaigns/; https://blog.lu
Suricata
ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361 - Outbound
suricata·2019-05-08·CVSS 9.8
CVE-2014-8361 [CRITICAL] ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361 - Outbound
ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361 - Outbound
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361 - Outbound"; flow:established,to_server; http.method; content:"POST"; http.request_header; header_lowercase; content:"soapaction|3a 20|urn|3a|schemas-upnp-org|3a|service|3a|WANIPConnection|3a|"; fast_pattern; startswith; http.request_body; content:"|3c|u|3a|AddPortMapping"; content:"|3c|NewRemoteHost|3e|"; distance:0; content:"|3c|NewInternalClient"; distance:0; content:"|3c 2f|NewInternalClient|3e|"; distance:0; content:"NewEnabled|3e|1"; distance:0; classtype:trojan-activity; sid:2027339; rev:4; metadata:attack_target IoT, created_at 2019_05_08, cve CVE_2014_8361, deployment
Suricata
ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361
suricata·2017-12-05·CVSS 9.8
CVE-2014-8361 [CRITICAL] ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361
ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361
Rule: alert http any any -> $HOME_NET 52869 (msg:"ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361"; flow:established,to_server; urilen:12; http.method; content:"POST"; http.uri; content:"/picdesc.xml"; http.header; header_lowercase; content:"soapaction|3a 20|urn|3a|schemas-upnp-org|3a|service|3a|WANIPConnection|3a|"; reference:url,blog.netlab.360.com/warning-satori-a-new-mirai-variant-is-spreading-in-worm-style-on-port-37215-and-52869-en/; reference:cve,CVE-2014-8361; reference:url,github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/realtek_miniigd_upnp_exec_noauth.rb; reference:url,www.exploit-db.com/exploits/37169/; classtype:attempted-user; sid:2025132; rev:4; me
Exploit-DB
Realtek SDK - Miniigd UPnP SOAP Command Execution (Metasploit)
exploitdb·2015-06-01
CVE-2014-8361 Realtek SDK - Miniigd UPnP SOAP Command Execution (Metasploit)
Realtek SDK - Miniigd UPnP SOAP Command Execution (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 'Realtek SDK Miniigd UPnP SOAP Command Execution',
'Description' => %q{
Different devices using the Realtek SDK with the miniigd daemon are vulnerable to OS command
injection in the UPnP SOAP interface. Since it is a blind OS command injection vulnerability,
there is no output for the executed command. This module has been tested successfully on a
Trendnet TEW-731BR router with emulation.
},
'Author' =>
[
'Ricky "HeadlessZeke" Lawshae', # Vulnerability discovery
'Michael Messner ' # Metasploit module
],
'License' => MSF_LICENSE,
'References' =>
[
['
Metasploit
D-Link Devices UPnP SOAP Command Execution
metasploit
D-Link Devices UPnP SOAP Command Execution
D-Link Devices UPnP SOAP Command Execution
Different D-Link Routers are vulnerable to OS command injection in the UPnP SOAP interface. Since it is a blind OS command injection vulnerability, there is no output for the executed command. This module has been tested on DIR-865 and DIR-645 devices.
Metasploit
Realtek SDK Miniigd UPnP SOAP Command Execution
metasploit
Realtek SDK Miniigd UPnP SOAP Command Execution
Realtek SDK Miniigd UPnP SOAP Command Execution
Different devices using the Realtek SDK with the miniigd daemon are vulnerable to OS command injection in the UPnP SOAP interface. Since it is a blind OS command injection vulnerability, there is no output for the executed command. This module has been tested successfully on a Trendnet TEW-731BR router with emulation.
Unit42
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
blogs_unit42·2026-07-15
CVE-2022-1388 TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
## TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
Chris Navarrete
Asher Davila
Doel Santos
Published: July 15, 2026
Malware
Threat Research
C2
DGA
Docker compose
Malware
TuxBot v3 Evolution
VirusTotal
XOR
## Executive Summary
We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
The malware authors leveraged an LLM to assist in their code development, yielding mixed results. While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed to remove before shipping.
Although the LLM clearly aided in constructing the botnet, several functions in the analyzed samples failed to work correctly. While a manual code review could hav
Greynoiseio
GreyNoise 2025 Mass Internet Exploitation Report: Attackers Are Moving Faster Than Ever — Are You Ready?
blogs_greynoiseio·2025-02-27
GreyNoise 2025 Mass Internet Exploitation Report: Attackers Are Moving Faster Than Ever — Are You Ready?
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bleepingcomputer
Malware exploits 5-year-old zero-day to infect end-of-life IP cameras
blogs_bleepingcomputer·2024-08-29·CVSS 8.7
CVE-2024-7029 [HIGH] Malware exploits 5-year-old zero-day to infect end-of-life IP cameras
## Malware exploits 5-year-old zero-day to infect end-of-life IP cameras
## Bill Toulas
The Corona Mirai-based malware botnet is spreading through a 5-year-old remote code execution (RCE) zero-day in AVTECH IP cameras, which have been discontinued for years and will not receive a patch.
The flaw, discovered by Akamai's Aline Eliovich, is tracked as CVE-2024-7029 and is a high-severity (CVSS v4 score: 8.7) issue in the "brightness" function of the cameras, allowing unauthenticated attackers to inject commands over the network using specially crafted requests.
Specifically, the easy-to-exploit flaw lies in the "brightness" argument in the "action=" parameter of the AVTECH cameras' firmware, intended to allow remote adjustments to the brightness of a camera.
The flaw impacts all AVTECH A
Fortinet
2022 IoT Threat Review | FortiGuard Labs
blogs_fortinet·2023-01-13·CVSS 8.8
[HIGH] 2022 IoT Threat Review | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
2022 IoT Threat Review
By Eduardo Altares, Joie Salvio and Roy Tay | January 13, 2023
FortiGuard Labs monitors the IoT botnet threat landscape for new and emerging campaigns. We do this with the assistance of our honeypots we have deployed to capture active attacks in the wild. This article provides insights into the data collected from our monitoring system over the past year.
Affected Platforms: Linux
Impacted Users: Any organization
Impact: Remote attackers gain control of the vulnerable systems
Severity Level: Critical
Attack Origins
Our distributed honeypot systems allow us to capture and monitor campaigns that are actively targeting IoT devices for infection. In most cases, these devices are turned into bots used to perform Distributed Denial o
Checkpoint
24th May – Threat Intelligence Report
blogs_checkpoint·2021-05-24
CVE-2021-21551 24th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has discovered multiple misconfiguration flaws in third party cloud services of Android applications, which have led to the exposure of sensitive personal data of more than 100 million Android users and developers. Many flaws were the result of improper configuration of real-time databases.
Check Point Harmo
Trendmicro
IoT Monitoring-Daten zu Threat Defense umwandeln
blogs_trendmicro·2020-10-14
IoT Monitoring-Daten zu Threat Defense umwandeln
Cyberbedrohungen
## IoT Monitoring-Daten zu Threat Defense umwandeln
Um seine Kunden noch besser vor Cyberbedrohungen zu schützen, verwendet Trend Micro die gesammelten Indicators of Compromise aus IoTAngriffen, um die Fähigkeit zur Erkennung von Bedrohungen zu verbessern.
By: Shimamura Makoto Oct 14, 2020 Read time: ( words)
Save to Folio
Originalartikel von Shimamura Makoto, Senior Security Specialist
Der Sicherheitsbericht zur Jahresmitte 2020 von Trend Micro weist im Vergleich zum zur zweiten Jahreshälfte 2019 eine Steigerung von 70 Prozent bei Angriffen auf Geräte und Router aus. Dazu gehören auch Attacken auf Internet-of-Things (IoT)-Systeme, die in ihrer Häufung beunruhigen. Die Sicherheitsforscher von Trend Micro überwachen die Trends bezüglich dieser Angriffe und untersuchte
Trendmicro
Transforming IoT Monitoring Data into Threat Defense
blogs_trendmicro·2020-10-08
Transforming IoT Monitoring Data into Threat Defense
IoT
# Transforming IoT Monitoring Data into Threat Defense
In this article, we feature data gathered from our continuous monitoring of C&C servers of botnets such as Mirai and Bashlite. We also share how this data is used to bolster the protection of IoT devices.
By: Shimamura Makoto
2020/10/08
Read time: ( words)
Save to Folio
In our midyear roundup report, we shared that in the first half of 2020, there was a 70% increase in inbound attacks on devices and routers compared with the second half of 2019. This data includes attacks on Internet of Things (IoT) systems, which remain alarming and prevalent.
With the aim of protecting customers effectively by continuously monitoring trends in IoT attacks, we examined Mirai and Bashlite (aka Qbot), two notorious IoT botnet malware types th
Unit42
Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
blogs_unit42·2019-12-13
Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
Threat Research Center
Threat Research
Malware
## Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
Ruchna Nigam
Published: December 13, 2019
Malware
Threat Research
Vulnerabilities
Echobot
IoT
IoT Vulnerability
Mirai
Mirai variant
## Executive Summary
Since the discovery of the Mirai variant using the binary name ECHOBOT in May 2019, it has resurfaced from time to time, using new infrastructure, and more remarkably, adding to the list of vulnerabilities it scans for, as a means to increase its attack surface with each evolution.
Unlike other Mirai variants, this particular variant stands out for the sheer number of exploits it incorporates, with the latest version having a total of 71 unique exploits, 13 of which haven’t been seen exploite
Unit42
Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
blogs_unit42·2019-12-13
Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
## Executive Summary
Since the discovery of the Mirai variant using the binary name ECHOBOT in May 2019, it has resurfaced from time to time, using new infrastructure, and more remarkably, adding to the list of vulnerabilities it scans for, as a means to increase its attack surface with each evolution.
Unlike other Mirai variants, this particular variant stands out for the sheer number of exploits it incorporates, with the latest version having a total of 71 unique exploits, 13 of which haven’t been seen exploited in the wild until now, ranging from extremely old CVEs from as long back as 2003, to recent vulnerabilities made public as recently as early December 2019. Based on this seemingly odd choice, one could risk a guess that the attackers could potentially be aiming for the sweet sp
Unit42
Home & Small Office Wireless Routers Exploited to Attack Gaming Servers
blogs_unit42·2019-10-31·CVSS 9.8
[CRITICAL] Home & Small Office Wireless Routers Exploited to Attack Gaming Servers
Threat Research Center
Threat Research
Cybercrime
## Home & Small Office Wireless Routers Exploited to Attack Gaming Servers
Asher Davila
Published: October 31, 2019
Cybercrime
Threat Research
Vulnerabilities
Botnet
DDoS
Exploit kit
IoT
WiFi routers
## Executive Summary
In September 2019, during the proactive IoT threat-hunting process conducted daily by the Unit 42 (formerly Zingbox security research) team, we discovered an updated Gafgyt variant attempting to infect IoT devices; specifically small office/home wireless routers of known commercial brands like Zyxel, Huawei, and Realtek. This Gafgyt variant is a competing botnet to the JenX botnet, which also uses remote code execution exploits to gain access and recruit routers into botnets to attack gaming servers - mos
Unit42
Home & Small Office Wireless Routers Exploited to Attack Gaming Servers
blogs_unit42·2019-10-31·CVSS 9.8
[CRITICAL] Home & Small Office Wireless Routers Exploited to Attack Gaming Servers
## Executive Summary
In September 2019, during the proactive IoT threat-hunting process conducted daily by the Unit 42 (formerly Zingbox security research) team, we discovered an updated Gafgyt variant attempting to infect IoT devices; specifically small office/home wireless routers of known commercial brands like Zyxel, Huawei, and Realtek. This Gafgyt variant is a competing botnet to the JenX botnet, which also uses remote code execution exploits to gain access and recruit routers into botnets to attack gaming servers - most notably those running the Valve Source engine - and cause a Denial of Service (DoS). This variant also competes against similar botnets, which we have found are frequently sold on Instagram. According to Shodan scans, there are more than 32,000 WiFi routers potentia
Trendmicro
Neko, Mirai and Bashlite Target Routers, Devices
blogs_trendmicro·2019-08-13
Neko, Mirai and Bashlite Target Routers, Devices
# Neko, Mirai and Bashlite Target Routers, Devices
Within a span of three weeks, our telemetry uncovered three notable malware variants of Neko, Mirai, and Bashlite. These malware variants enlist infected routers to botnets that are capable of launching distributed denial of service (DDoS) attacks.
By: Augusto Remillano II, Jakub Urbanec
Aug 13, 2019
Read time: ( words)
Save to Folio
Within a span of three weeks, our telemetry uncovered three notable malware variants of Neko, Mirai, and Bashlite. On July 22, 2019, we saw and started analyzing a Neko botnet sample, then observed another sample with additional exploits the following week. A Mirai variant that calls itself “Asher” surfaced on July 30, then a Bashlite variant called “Ayedz” the following week. These malware variants enlis
Trendmicro
Neko, Mirai and Bashlite Target Routers, Devices
blogs_trendmicro·2019-08-13
Neko, Mirai and Bashlite Target Routers, Devices
# Neko, Mirai and Bashlite Target Routers, Devices
Within a span of three weeks, our telemetry uncovered three notable malware variants of Neko, Mirai, and Bashlite. These malware variants enlist infected routers to botnets that are capable of launching distributed denial of service (DDoS) attacks.
By: Augusto Remillano II, Jakub Urbanec
2019/08/13
Read time: ( words)
Save to Folio
Within a span of three weeks, our telemetry uncovered three notable malware variants of Neko, Mirai, and Bashlite. On July 22, 2019, we saw and started analyzing a Neko botnet sample, then observed another sample with additional exploits the following week. A Mirai variant that calls itself “Asher” surfaced on July 30, then a Bashlite variant called “Ayedz” the following week. These malware variants enlist
Unit42
New Mirai Variant Adds 8 New Exploits, Targets Additional IoT Devices
blogs_unit42·2019-06-07·CVSS 9.8
[CRITICAL] New Mirai Variant Adds 8 New Exploits, Targets Additional IoT Devices
Executive Summary
Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016 when it took down several notable targets.
As part of this ongoing research, we’ve recently discovered a new variant of Mirai that has eight new exploits against a wide range of embedded devices. These newly targeted devices range from wireless presentation systems to set-top-boxes, SD-WANs, and even smart home controllers.
Mirai initially made use of default credentials to gain access to devices. However, since the end of 2017, samples of the family have increasingly been observed making use of publicly available exploits to propagate and run on vulnerable devices.
2018
Unit42
New Mirai Variant Adds 8 New Exploits, Targets Additional IoT Devices
blogs_unit42·2019-06-07·CVSS 9.8
CVE-2017-5174 [CRITICAL] New Mirai Variant Adds 8 New Exploits, Targets Additional IoT Devices
Threat Research Center
Threat Research
Malware
## New Mirai Variant Adds 8 New Exploits, Targets Additional IoT Devices
Ruchna Nigam
Published: June 6, 2019
Malware
Threat Research
Vulnerabilities
CVE-2017-5174
CVE-2018-11510
CVE-2018-17173
CVE-2018-6961
CVE-2019-2725
CVE-2019-3929
Exploits
IoT
Linux
Mirai
Executive Summary
Palo Alto Networks Unit 42 has been tracking the evolution of the Mirai malware, known for targeting embedded devices with the primary intent of launching DDoS attacks and self-propagation, since 2016 when it took down several notable targets.
As part of this ongoing research, we’ve recently discovered a new variant of Mirai that has eight new exploits against a wide range of embedded devices. These newly targeted devices range from wireless prese
Trendmicro
New Mirai Variant Uses Multiple Exploits
blogs_trendmicro·2019-05-23
New Mirai Variant Uses Multiple Exploits
Exploits & Vulnerabilities
# New Mirai Variant Uses Multiple Exploits
We discovered a new variant of Mirai that uses a total of 13 different exploits, almost all of which have been used in previous Mirai-related attacks. Typical of Mirai variants, it has backdoor and distributed denial-of-service (DDoS) capabilities.
By: Augusto Remillano II, Jakub Urbanec
May 23, 2019
Read time: ( words)
Save to Folio
We discovered a new variant of Mirai (detected as Backdoor.Linux.MIRAI.VWIPT) that uses a total of 13 different exploits, almost all of which have been used in previous Mirai-related attacks. Typical of Mirai variants, it has backdoor and distributed denial-of-service (DDoS) capabilities. However, this case stands out as the first to have used all 13 exploits together in a single campa
Trendmicro
New Mirai Variant Uses Multiple Exploits
blogs_trendmicro·2019-05-23
New Mirai Variant Uses Multiple Exploits
Exploits & Vulnerabilities
# New Mirai Variant Uses Multiple Exploits
We discovered a new variant of Mirai that uses a total of 13 different exploits, almost all of which have been used in previous Mirai-related attacks. Typical of Mirai variants, it has backdoor and distributed denial-of-service (DDoS) capabilities.
By: Augusto Remillano II, Jakub Urbanec
2019/05/23
Read time: ( words)
Save to Folio
We discovered a new variant of Mirai (detected as Backdoor.Linux.MIRAI.VWIPT) that uses a total of 13 different exploits, almost all of which have been used in previous Mirai-related attacks. Typical of Mirai variants, it has backdoor and distributed denial-of-service (DDoS) capabilities. However, this case stands out as the first to have used all 13 exploits together in a single campaig
Unit42
Mirai Compiled for New Processors Surfaces in the Wild
blogs_unit42·2019-04-08
Mirai Compiled for New Processors Surfaces in the Wild
Threat Research Center
Threat Research
Malware
## Mirai Compiled for New Processors Surfaces in the Wild
Ruchna Nigam
Published: April 8, 2019
Malware
Threat Research
Botnet
DDoS
IoT
Linux
Mirai
## Executive Summary
In late February 2019, Unit 42 discovered Mirai samples compiled for new processors/architectures not previously seen before. Despite the source code being publicly released In October of 2016, the malware has, until now, only been found targeting a fixed set of processors/architectures.
Unit 42 has found the newly discovered samples are compiled for Altera Nios II, OpenRISC, Tensilica Xtensa, and Xilinx MicroBlaze processors. This is not the first time Mirai has been expanded for new processor architectures, samples targeting ARC CPUs were discovered in Janu
Unit42
Mirai Compiled for New Processors Surfaces in the Wild
blogs_unit42·2019-04-08
Mirai Compiled for New Processors Surfaces in the Wild
# Executive Summary
In late February 2019, Unit 42 discovered Mirai samples compiled for new processors/architectures not previously seen before. Despite the source code being publicly released In October of 2016, the malware has, until now, only been found targeting a fixed set of processors/architectures.
Unit 42 has found the newly discovered samples are compiled for Altera Nios II, OpenRISC, Tensilica Xtensa, and Xilinx MicroBlaze processors. This is not the first time Mirai has been expanded for new processor architectures, samples targeting ARC CPUs were discovered in January 2018. Yet this development shows that Mirai developers continue to actively innovate, targeting a growing array of IoT devices. The malware gained notoriety in 2016 for its use in massive denial of service att
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities
blogs_trendmicro·2019-03-06
UPnP-enabled Home Devices and Vulnerabilities
# UPnP-enabled Home Devices and Vulnerabilities
UPnP convenience comes security holes that range from attackers gaining control of devices to bypassing firewall protections. We looked into UPnP-related events in home networks and found that many users still have UPnP enabled in their devices."
By: Tony Yang
Mar 06, 2019
Read time: ( words)
Save to Folio
Earlier this year, users of Chromecast streaming dongles, Google Home devices, and smart TVs were inundated with a message promoting YouTuber PewDiePie’s channel. The hijacking is said to be part of an ongoing subscriber count battle on the video sharing site. The hackers behind it reportedly took advantage of poorly configured routers that had the Universal Plug and Play (UPnP) service enabled, which caused the routers to forward publ
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities
blogs_trendmicro·2019-03-06
UPnP-enabled Home Devices and Vulnerabilities
# UPnP-enabled Home Devices and Vulnerabilities
UPnP convenience comes security holes that range from attackers gaining control of devices to bypassing firewall protections. We looked into UPnP-related events in home networks and found that many users still have UPnP enabled in their devices."
By: Tony Yang
2019/03/06
Read time: ( words)
Save to Folio
Earlier this year, users of Chromecast streaming dongles, Google Home devices, and smart TVs were inundated with a message promoting YouTuber PewDiePie’s channel. The hijacking is said to be part of an ongoing subscriber count battle on the video sharing site. The hackers behind it reportedly took advantage of poorly configured routers that had the Universal Plug and Play (UPnP) service enabled, which caused the routers to forward public
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities
blogs_trendmicro·2019-03-06
UPnP-enabled Home Devices and Vulnerabilities
## UPnP-enabled Home Devices and Vulnerabilities
UPnP convenience comes security holes that range from attackers gaining control of devices to bypassing firewall protections. We looked into UPnP-related events in home networks and found that many users still have UPnP enabled in their devices."
By: Tony Yang 2019/03/06 Read time: ( words)
Save to Folio
Earlier this year, users of Chromecast streaming dongles, Google Home devices, and smart TVs were inundated with a message promoting YouTuber PewDiePie’s channel. The hijacking is said to be part of an ongoing subscriber count battle on the video sharing site. The hackers behind it reportedly took advantage of poorly configured routers that had the Universal Plug and Play (UPnP) service enabled, which caused the routers to forward public
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities
blogs_trendmicro·2019-03-06
UPnP-enabled Home Devices and Vulnerabilities
## UPnP-enabled Home Devices and Vulnerabilities
UPnP convenience comes security holes that range from attackers gaining control of devices to bypassing firewall protections. We looked into UPnP-related events in home networks and found that many users still have UPnP enabled in their devices."
By: Tony Yang Mar 06, 2019 Read time: ( words)
Save to Folio
Earlier this year, users of Chromecast streaming dongles, Google Home devices, and smart TVs were inundated with a message promoting YouTuber PewDiePie’s channel. The hijacking is said to be part of an ongoing subscriber count battle on the video sharing site. The hackers behind it reportedly took advantage of poorly configured routers that had the Universal Plug and Play (UPnP) service enabled, which caused the routers to forward publ
Trendmicro
Botnets nutzen ThinkPHP-Schwachstelle zur Verbreitung
blogs_trendmicro·2019-01-30·CVSS 9.8
[CRITICAL] Botnets nutzen ThinkPHP-Schwachstelle zur Verbreitung
Ausnutzung von Schwachstellen
## Botnets nutzen ThinkPHP-Schwachstelle zur Verbreitung
Cyberkriminelle können Hakai und Yowai einfach dazu missbrauchen, Webserver zu kapern und Websites anzugreifen.
By: Augusto Remillano II Jan 30, 2019 Read time: ( words)
Save to Folio
Originalbeitrag von Augusto Remillano II
Eine neue Mirai -Variante Yowai und die Gafgyt -Variante Hakai nutzen eine Schwachstelle (im Dezember 2018 gepatcht) im quelloffenen PHP Framework ThinkPHP aus, um ein Botnet via Websites zu verbreiten, die mit dem Framework erstellt wurden. Die Cyberkriminellen nutzen das Framework, um Dictionary-Angriffe auf Standard-Credentials zu starten und dann auf Webserver zuzugreifen. Das Ziel sind Distributed Denial of Service ( DDoS )-Angriffe. Die Telemetriedaten zeigten, dass diese
Zscaler
A Sneak Peek into Recent IoT Attacks | Zscaler Blog
blogs_zscaler·2019-01-28
A Sneak Peek into Recent IoT Attacks | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Trendmicro
ThinkPHP Vulnerability Abused by Botnets
blogs_trendmicro·2019-01-25
ThinkPHP Vulnerability Abused by Botnets
IoT
## ThinkPHP Vulnerability Abused by Botnets
We found a new Mirai variant we’ve called Yowai and Gafgyt variant Hakai abusing a ThinkPHP flaw for propagation and DDoS attacks.
By: Augusto Remillano II 2019/01/25 Read time: ( words)
Save to Folio
Cybercriminals are exploiting a ThinkPHP vulnerability — one that was disclosed and patched in December 2018 — for botnet propagation by a new Mirai variant we’ve called Yowai and Gafgyt variant Hakai. Cybercriminals use websites created using the PHP framework to breach web servers via dictionary attacks on default credentials and gain control of these routers for distributed denial of service attacks ( DDoS ). Our telemetry showed that these two particular malware types caused a sudden increase in attacks and infection attempts from Janua
Trendmicro
ThinkPHP Vulnerability Abused by Botnets
blogs_trendmicro·2019-01-25
ThinkPHP Vulnerability Abused by Botnets
IoT
# ThinkPHP Vulnerability Abused by Botnets
We found a new Mirai variant we’ve called Yowai and Gafgyt variant Hakai abusing a ThinkPHP flaw for propagation and DDoS attacks.
By: Augusto Remillano II
Jan 25, 2019
Read time: ( words)
Save to Folio
Cybercriminals are exploiting a ThinkPHP vulnerability — one that was disclosed and patched in December 2018 — for botnet propagation by a new Mirai variant we’ve called Yowai and Gafgyt variant Hakai. Cybercriminals use websites created using the PHP framework to breach web servers via dictionary attacks on default credentials and gain control of these routers for distributed denial of service attacks (DDoS). Our telemetry showed that these two particular malware types caused a sudden increase in attacks and infection attempts from Janua
Trendmicro
ThinkPHP Vulnerability Abused by Botnets
blogs_trendmicro·2019-01-25
ThinkPHP Vulnerability Abused by Botnets
IoT
# ThinkPHP Vulnerability Abused by Botnets
We found a new Mirai variant we’ve called Yowai and Gafgyt variant Hakai abusing a ThinkPHP flaw for propagation and DDoS attacks.
By: Augusto Remillano II
2019/01/25
Read time: ( words)
Save to Folio
Cybercriminals are exploiting a ThinkPHP vulnerability — one that was disclosed and patched in December 2018 — for botnet propagation by a new Mirai variant we’ve called Yowai and Gafgyt variant Hakai. Cybercriminals use websites created using the PHP framework to breach web servers via dictionary attacks on default credentials and gain control of these routers for distributed denial of service attacks (DDoS). Our telemetry showed that these two particular malware types caused a sudden increase in attacks and infection attempts from January
Trendmicro
ThinkPHP Vulnerability Abused by Botnets
blogs_trendmicro·2019-01-25
ThinkPHP Vulnerability Abused by Botnets
IoT
## ThinkPHP Vulnerability Abused by Botnets
We found a new Mirai variant we’ve called Yowai and Gafgyt variant Hakai abusing a ThinkPHP flaw for propagation and DDoS attacks.
By: Augusto Remillano II Jan 25, 2019 Read time: ( words)
Save to Folio
Cybercriminals are exploiting a ThinkPHP vulnerability — one that was disclosed and patched in December 2018 — for botnet propagation by a new Mirai variant we’ve called Yowai and Gafgyt variant Hakai. Cybercriminals use websites created using the PHP framework to breach web servers via dictionary attacks on default credentials and gain control of these routers for distributed denial of service attacks ( DDoS ). Our telemetry showed that these two particular malware types caused a sudden increase in attacks and infection attempts from Jan
Fortinet
DDoS-for-Hire Service Powered by Bushido Botnet
blogs_fortinet·2018-10-26
DDoS-for-Hire Service Powered by Bushido Botnet
FORTIGUARD LABS THREAT RESEARCH
DDoS-for-Hire Service Powered by Bushido Botnet
By Rommel Joven and Evgeny Ananin | October 26, 2018
Distributed Denial-of-Service (DDoS) service offerings, often disguised as legitimate “booter” or “stresser” services, continue to increase in the cyber underground market. This relatively new Crime-as-a-Service trend has created an entry point for novice DDoS attackers, offering a simple option to anonymously attack nearly any website and forcing it offline for a small fee.
Sadly, due to the public release of the source code of some popular bots, building a botnet to provide these services is simpler than ever. A quick Google search returns lists of resources for botnet builders, usually with complete step-by-step instructions. Being able to re-use and ev
Securelist
New trends in the world of IoT threats
blogs_securelist·2018-09-18
New trends in the world of IoT threats
Authors
Mikhail Kuzin
Yaroslav Shmelev
Vladimir Kuskov
Cybercriminals’ interest in IoT devices continues to grow: in H1 2018 we picked up three times as many malware samples attacking smart devices as in the whole of 2017. And in 2017 there were ten times more than in 2016. That doesn’t bode well for the years ahead.
We decided to study what attack vectors are deployed by cybercriminals to infect smart devices, what malware is loaded into the system, and what it means for device owners and victims of freshly armed botnets.
Number of malware samples for IoT devices in Kaspersky Lab’s collection, 2016-2018.
One of the most popular attack and infection vectors against devices remains cracking Telnet passwords. In Q2 2018, there were three times as many such attacks against our honeypot
Securelist
New trends in the world of IoT threats
blogs_securelist·2018-09-18
New trends in the world of IoT threats
Authors
- Mikhail Kuzin
- Yaroslav Shmelev
- Vladimir Kuskov
Cybercriminals’ interest in IoT devices continues to grow: in H1 2018 we picked up three times as many malware samples attacking smart devices as in the whole of 2017. And in 2017 there were ten times more than in 2016. That doesn’t bode well for the years ahead.
We decided to study what attack vectors are deployed by cybercriminals to infect smart devices, what malware is loaded into the system, and what it means for device owners and victims of freshly armed botnets.
Number of malware samples for IoT devices in Kaspersky Lab’s collection, 2016-2018.
One of the most popular attack and infection vectors against devices remains cracking Telnet passwords. In Q2 2018, there were three times as many such attacks against our hone
Unit42
Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet Campaigns
blogs_unit42·2018-07-20·CVSS 9.8
[CRITICAL] Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet Campaigns
The end of May 2018 has marked the emergence of three malware campaigns built on publicly available source code for the Mirai and Gafgyt malware families that incorporate multiple known exploits affecting Internet of Things (IoT) devices.
Samples belonging to these campaigns incorporate as many as eleven exploits within a single sample, beating the IoT Reaper malware, which borrowed some of the Mirai source code but also came with an integrated LUA environment that incorporated nine exploits in its code.
In their newest evolution, samples also target the D-Link DSL-2750B OS Command Injection vulnerability, only a few weeks after the publication of its Metasploit module on the 25th of May (even though the vulnerability has been public knowledge since February of 2016).
While exploring sa
Unit42
Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet Campaigns
blogs_unit42·2018-07-20·CVSS 9.8
[CRITICAL] Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet Campaigns
Threat Research Center
Threat Research
Malware
## Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet Campaigns
Ruchna Nigam
Published: July 20, 2018
Malware
Threat Research
Botnet
DDoS
Exploits
Gafgyt
Hakai
IoT
Linux
Mirai
Okane
Omni
The end of May 2018 has marked the emergence of three malware campaigns built on publicly available source code for the Mirai and Gafgyt malware families that incorporate multiple known exploits affecting Internet of Things (IoT) devices.
Samples belonging to these campaigns incorporate as many as eleven exploits within a single sample, beating the IoT Reaper malware, which borrowed some of the Mirai source code but also came with an integrated LUA environment that incorporated nine exploits in its code.
In their newest evolution, samples
Trendmicro
Identifying Top Vulnerabilities in Networks
blogs_trendmicro·2018-05-29
Identifying Top Vulnerabilities in Networks
IoT
# Identifying Top Vulnerabilities in Networks
Our findings homed in on known vulnerabilities, IoT botnets with top vulnerability detections, and devices that are affected. Our scanning covered different OSs, including Linux, Mac, Windows, Android, iOS, and other SDK platforms.
By: Tony Yang, Adam Huang, Louis Tsai
2018/05/29
Read time: ( words)
Save to Folio
We have noted time and again how compromising networks and connected devices is rooted in finding weak points in the system. Often, these are in the form of vulnerabilities. Worse, vulnerabilities that aren’t even new. In the context of the internet of things (IoT) and noteworthy security incidents related to it, these vulnerabilities have afforded attackers means to use unsecure devices to facilitate malicious activities suc
Trendmicro
Device Vulnerabilities in the Connected Home
blogs_trendmicro·2018-04-16
Device Vulnerabilities in the Connected Home
Smart Home
# Device Vulnerabilities in the Connected Home
In the past year, we took a closer look at the security of IoT devices around the world. We tested devices widely used in the Japan market and available in different Amazon regions to find out whether remote code execution (RCE) is possible.
By: Dove Chiu, Kenney Lu, Tim Yeh
2018/04/16
Read time: ( words)
Save to Folio
If there is anything to be learned from the massive attacks that have been seen on connected devices, it is that the internet of things (IoT) is riddled with vulnerabilities. We have seen this time and again with how botnets are created from system weaknesses and have harnessed poor basic security to disrupt many devices and services.
In the past year, we embarked on a closer look at the security of IoT devices
Securelist
Threat Landscape for Industrial Automation Systems in H2 2017
blogs_securelist·2018-03-26
Threat Landscape for Industrial Automation Systems in H2 2017
Table of Contents
Overview of ICS vulnerabilities identified in 2017
Vulnerabilities in various ICS components
Number of vulnerabilities identified
Analysis by Industry
Severity levels of the vulnerabilities identified
Types of vulnerabilities identified
Vulnerable ICS components
Vulnerabilities in industrial protocols
Impact of vulnerabilities in ‘traditional’ technologies on industrial systems
IoT device vulnerabilities
Vulnerabilities identified by Kaspersky Lab ICS CERT
Number of vulnerabilities identified
Number of CVE entries published
Capabilities provided by the vulnerabilities identified
Vulnerabilities in ICS components
Severity ratings of the vulnerabilities identified
Vulnerabilities in OPC UA implementations
Vulnerabilities in third-party hardware-based and s
Securelist
Threat Landscape for Industrial Automation Systems in H2 2017
blogs_securelist·2018-03-26
Threat Landscape for Industrial Automation Systems in H2 2017
Table of Contents
- Overview of ICS vulnerabilities identified in 2017
- Vulnerabilities identified by Kaspersky Lab ICS CERT
- Malware in industrial automation systems
- Threat statistics
- Our recommendations
Authors
- Kaspersky ICS CERT
For many years, Kaspersky Lab experts have been uncovering and researching cyberthreats that target a variety of information systems – those of commercial and government organizations, banks, telecoms operators, industrial enterprises, and individual users. In this report, Kaspersky Lab Industrial Control Systems Cyber Emergency Response Team (Kaspersky Lab ICS CERT) publishes the findings of its research on the threat landscape for industrial automation systems conducted during the second half of 2017.
The main objective of these publications is t
Fortinet
Satori Adds Known Exploit Chain to Enslave Wireless IP Cameras
blogs_fortinet·2018-02-02
Satori Adds Known Exploit Chain to Enslave Wireless IP Cameras
FORTIGUARD LABS THREAT RESEARCH
Satori Adds Known Exploit Chain to Enslave Wireless IP Cameras
By David Maciejak, Jasper Manuel and Rommel Joven | February 02, 2018
Satori, a Mirai based IoT bot, has been one of the most actively updated exploits in recent months. It is believed that the hacker behind this bot is also the author of other Mirai variants, known as Okiru, and Masuta.
FortiGuard Labs researchers recently observed a new Satori version that had added a known exploit chain (one which had been used in the past by the Persirai bot) to enable it to spread to vulnerable devices, particularly, wireless IP cameras that run a vulnerable custom version of the GoAhead web server. This exploit chain targets two vulnerabilities. One, discovered by Istvan Toth and which was detailed in th
Unit42
IoT Malware Evolves to Harvest Bots by Exploiting a Zero-day Home Router Vulnerability
blogs_unit42·2018-01-11·CVSS 9.8
CVE-2014-8361 [CRITICAL] IoT Malware Evolves to Harvest Bots by Exploiting a Zero-day Home Router Vulnerability
Summary
In early December 2017, 360 Netlab discovered a new malware family which they named Satori. Satori is a derivative of Mirai and exploits two vulnerabilities: CVE-2014-8361 a code execution vulnerability in the miniigd SOAP service in Realtek SDK, and CVE 2017-17215 a newly discovered vulnerability in Huawei’s HG532e home gateway patched in early December 2017.
Palo Alto Networks Unit 42 investigated Satori, and from our intelligence data, we have found there are three Satori variants. The first of these variants appeared in April 2017, eight months before these most recent attacks.
We also found evidence indicating that the version of Satori exploiting CVE 2017-17215 was active in late November 2017, before Huawei patched the vulnerability. This means that this version of Satori
Unit42
IoT Malware Evolves to Harvest Bots by Exploiting a Zero-day Home Router Vulnerability
blogs_unit42·2018-01-11·CVSS 9.8
CVE-2014-8361 [CRITICAL] IoT Malware Evolves to Harvest Bots by Exploiting a Zero-day Home Router Vulnerability
Threat Research Center
Threat Research
Vulnerabilities
## IoT Malware Evolves to Harvest Bots by Exploiting a Zero-day Home Router Vulnerability
Cong Zheng
Claud Xiao
Yanhui Jia
Published: January 11, 2018
Malware
Threat Research
Vulnerabilities
Botnet
IoT
Mirai
Satori
Zero-day
Summary
In early December 2017, 360 Netlab discovered a new malware family which they named Satori . Satori is a derivative of Mirai and exploits two vulnerabilities: CVE-2014-8361 a code execution vulnerability in the miniigd SOAP service in Realtek SDK, and CVE 2017-17215 a newly discovered vulnerability in Huawei’s HG532e home gateway patched in early December 2017.
Palo Alto Networks Unit 42 investigated Satori, and from our intelligence data, we have found there are three Satori variants. The
Fortinet
Rise of One More Mirai Worm Variant
blogs_fortinet·2017-12-12·CVSS 9.8
[CRITICAL] Rise of One More Mirai Worm Variant
FORTIGUARD LABS THREAT RESEARCH
Rise of One More Mirai Worm Variant
By David Maciejak | December 12, 2017
Not long after a new strain of the Akuma malware was discovered targeting ZyXEL devices with a new series of login/password attacks, FortiGuard Labs last week also began detecting strange scanning activities on uncommon TCP ports 52869 and 37215. We and other threat research teams quickly began to suspect that these were tied together, and that there was a new botnet out there.
With some focused research, the new Satori botnet, or “Okiru” – as it was named by its malevolent author – came to light. Okiru is a Japanese word that can be translated to “to get up” or “to rise”. Okiru first appeared on our radar at the end of October 2017, but during the first week of December it signific
Trendmicro
The Reigning King, Challengers of IP Camera Botnets
blogs_trendmicro·2017-06-08
The Reigning King, Challengers of IP Camera Botnets
Malware
# The Reigning King, Challengers of IP Camera Botnets
Early last month we discussed a new Internet of Things (IoT) botnet called Persirai (detected by Trend Micro as ELF_PERSIRAI.A), which targets over 1000 Internet Protocol (IP) camera models.
By: Kenney Lu, Tim Yeh, Dove Chiu
2017/06/08
Read time: ( words)
Save to Folio
Update as of June 21, 2017, 9:00 PM CDT to clarify a statement to emphasize that embedded JavaScript code was unable to be executed on the client side since IoT devices were too weak to execute JavaScript code locally. Also fixed ASUS Router Infosvr name.
Early last month we discussed a new Internet of Things (IoT) botnet called Persirai (detected by Trend Micro as ELF_PERSIRAI.A), which targets over 1000 Internet Protocol (IP) camera models. Currently, thr
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
GreyNoise Intelligence Publishes Second Annual Retrospective to Help International Cybersecurity Community Defend Against Internet Exploitation
blogs_greynoiseio
GreyNoise Intelligence Publishes Second Annual Retrospective to Help International Cybersecurity Community Defend Against Internet Exploitation
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Threat Intel
Nexus Zeta
threat_intel
Nexus Zeta
# Threat Actor: Nexus Zeta
## Description
Nexus Zeta is no stranger when it comes to implementing SOAP related exploits. The threat actor has already been observed in implementing two other known SOAP related exploits, CVE-2014–8361 and CVE-2017–17215 in his Satori botnet project. A third SOAP exploit, TR-069 bug has also been observed previously in IoT botnets. This makes EDB 38722 the fourth SOAP related exploit which is discovered in the wild by IoT botnets.
## Associated Malware Families (1)
elf.masuta
http://jvn.jp/en/jp/JVN47580234/index.htmlhttp://jvn.jp/en/jp/JVN67456944/index.htmlhttp://packetstormsecurity.com/files/132090/Realtek-SDK-Miniigd-UPnP-SOAP-Command-Execution.htmlhttp://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055http://www.securityfocus.com/bid/74330http://www.zerodayinitiative.com/advisories/ZDI-15-155/https://sensorstechforum.com/hinatabot-cve-2014-8361-ddos/https://web.archive.org/web/20150909230440/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055https://www.exploit-db.com/exploits/37169/http://jvn.jp/en/jp/JVN47580234/index.htmlhttp://jvn.jp/en/jp/JVN67456944/index.htmlhttp://packetstormsecurity.com/files/132090/Realtek-SDK-Miniigd-UPnP-SOAP-Command-Execution.htmlhttp://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055http://www.securityfocus.com/bid/74330http://www.zerodayinitiative.com/advisories/ZDI-15-155/https://sensorstechforum.com/hinatabot-cve-2014-8361-ddos/https://web.archive.org/web/20150909230440/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055https://www.exploit-db.com/exploits/37169/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-8361
2015-05-01
Published
2023-09-18
Added to CISA KEV
Exploited in the wild