The Mirai clone adds a dozen new exploits targeting corporate IoT devices.

Researchers have discovered a new clone of the well-known Mirai botnet, targeted at IoT devices. This time, embedded devices intended for use in business environments are under threat. The ultimate goal of the attackers is to gain control over high-bandwidth devices and carry out large-scale DDoS attacks.

The Mirai clone adds a dozen new exploits targeting corporate IoT devices.

Note:
At the time of translating, I was unaware that a similar article already exists on Habr. a similar article.

The authors of the original Mirai have already been arrested, but the availability source code, published in 2016, allows new attackers to create their botnets based on it. For instance, Satory and Okiru.

The original Mirai first appeared in 2016. It infected routers, IP cameras, DVRs, and other devices that often have default passwords, as well as devices using outdated versions of Linux.

The new variant of Mirai is designed for corporate devices

The new botnet was discovered by a research team Unit 42 from Palo Alto Networks. Its distinction from other clones is that it is aimed at corporate devices, including the wireless presentation systems WePresent WiPG-1000 and LG Supersign televisions.

The remote access execution exploit for LG Supersign televisions (CVE-2018-17173) became available in September last year. The exploit for WePresent WiPG-1000 was published in 2017. Overall, the bot is equipped with 27 exploits, 11 of which are new. The set of 'unusual default credentials' has also been expanded for dictionary attacks. The new variant of Mirai also targets various embedded hardware, such as:

  • Linksys routers
  • ZTE routers
  • DLink routers
  • Storage network devices
  • NVRs and IP cameras

'These new features give the botnet a larger attack surface,' researchers from Unit 42 stated in their blog. 'In particular, targeting corporate communication channels allows it to seize greater bandwidth, ultimately leading to increased firepower for DDoS attacks.'

This incident highlights the need for companies to monitor IoT devices in their networks, ensure proper security configurations, and regularly update their systems.
.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster