Moobot botnet is back and targets vulnerable D
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-2051 | Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life. Do: Because the DIR-645 is end-of-life, CISA's required action is to disconnect it; replace the device where possible, or at minimum apply the latest available D-Link firmware for the DIR-645 and ensure the management/HNAP interface is not reachable from the internet (block or restrict remote administration on the WAN side). Check the device for signs of botnet infection, such as unexpected outbound traffic or unexpected HNAP POST/SOAP requests, and prioritize this fix given the 97.1% EPSS score and known in-the-wild exploitation. | — | 97% | KEV |
| largetens of thousands of internet-exposed devices (est.; far more DIR-645 units exist behind NAT given the product's broad consumer/SOHO distribution) | |
| CVE-2018-6530 | Unauthenticated OS Command Injection in D-Link DIR-860L/865L/868L/880L Routers CVE-2018-6530 is an unauthenticated OS command injection flaw (CWE-78) in the SOAP interface (soap.cgi, handled by soapcgi_main in the cgibin binary) of several D-Link routers. A remote attacker sends a crafted request to soap.cgi containing a malicious 'service' parameter, causing arbitrary OS commands to execute on the router with no credentials or user interaction required. Successful exploitation yields full command execution on the device, enabling takeover, credential theft, or recruitment into botnets. Affected users are anyone running a D-Link DIR-860L, DIR-865L, DIR-868L, or DIR-880L on firmware at or below the versions listed in the advisory. Exploitation is active in the wild: CISA added the flaw to the KEV catalog on 2022-09-08 with known ransomware use, the Mirai variant MooBot/Moobot has been exploiting vulnerable D-Link routers to build botnets, and EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile). Do: Apply the latest available firmware from D-Link — the vendor advisory states that the fix released under CVE-2018-20114 properly patches this vulnerability. Because all four affected models have reached end-of-life, CISA recommends disconnecting any affected device still in use if no supported firmware is available, and replacing it if it is internet-facing. As an interim mitigation, block or restrict WAN access to the router's web/SOAP (soap.cgi/HNAP) interface and check device logs for unexpected outbound connections indicative of MooBot/Mirai compromise. | 9.8 | 97% | KEV ransomware PoC |
| massorder of 100,000+ internet-exposed devices, with total installed units across the four consumer router models plausibly in the millions (estimate) | |
| CVE-2021-36260 | Unauthenticated Command Injection in Hikvision Device Web Server CVE-2021-36260 is a command injection flaw (CWE-78) in the web server embedded in a wide range of Hikvision security camera and related devices, caused by insufficient input validation. An attacker triggers it by sending a crafted HTTP request to the device's web management interface, allowing commands to be executed on the device without authentication. Successful exploitation grants unauthenticated remote code execution on the camera or recorder, letting an attacker take control of the device, pivot into the surrounding network, or use the devices as a botnet platform. Any Hikvision device running the affected web server firmware is at risk, which includes cameras, recorders, and other surveillance hardware deployed in homes, businesses, and government facilities. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10 and carries a 99.9% EPSS probability of exploitation within 30 days, while no public proof-of-concept code is cataloged in the provided data and no CVSS score has been issued yet. Do: Apply firmware updates issued by Hikvision per the vendor's instructions, as required by CISA's KEV listing for this vulnerability. Restrict the device web management interface to trusted networks or VPN access and avoid direct internet exposure. Review web server logs for anomalous HTTP requests to the device interface and signs of command execution, and prioritize internet-facing devices for patching first. | 9.8 | 100% | KEV PoC ×3 |
| massmillions of installed devices, with roughly hundreds of thousands to over a million Hikvision web interfaces exposed to the internet | |
| CVE-2022-26258 | Unauthenticated Remote Command Execution in D-Link DIR-820L Router CVE-2022-26258 is an unauthenticated OS command injection (CWE-78) in D-Link DIR-820L router firmware, confirmed in version 1.05B03, reachable through the HTTP POST 'get set ccp' command interface. A remote attacker with no credentials and no user interaction can send a crafted HTTP POST request to this endpoint to execute arbitrary operating-system commands on the device. Successful exploitation yields full control of the router, providing a foothold for traffic interception, device enlistment into botnets, and lateral access to the home or small-office network behind it. Only users running the affected D-Link DIR-820L, an end-of-life consumer router, are affected, and no fixed firmware version is provided in the available data. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08 with a 92% EPSS score, and public reporting describes the Mirai-variant MooBot botnet targeting vulnerable D-Link devices. Do: Because the DIR-820L is end-of-life and CISA's required action is to disconnect it if still in use, replace or retire the router; check the model and firmware version on the device's status/admin page (1.05B03 is confirmed vulnerable). If replacement is not immediate, disconnect the device from the internet or restrict exposure with firewall rules so the HTTP management interface is not reachable by untrusted hosts, and watch for Mirai-variant (MooBot) botnet traffic patterns. No fixed firmware version is provided in the available data, so upgrading alone is not a documented remedy. | 9.8 | 92% | KEV PoC ×2 |
| large≈10,000–100,000 internet-exposed DIR-820L devices (order-of-magnitude estimate; a widely sold but end-of-life consumer router) | |
| CVE-2022-28958 | Rejected reason: DO NOT USE THIS CVE RECORD. Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. NVD description · AI analysis pending | — | — | — | — |
Full article396 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 07, 2022

The Moobot botnet is behind a new wave of attacks that started in early August and that target vulnerable D-Link routers.
Palo Alto Network’s Unit 42 researchers reported a new wave of attacks launched by the Moobot botnet that target vulnerable D-Link routers.
The Mirai-based Moobot botnet was first documented by Palo Alto Unit 42 researchers in February 2021, in November 2021, it started exploiting a critical command injection flaw (CVE-2021-36260) in the webserver of several Hikvision products.
Now the MooBot has re-emerged in a new attack wave of attacks that started in August, targeting vulnerable D-Link routers. The botnet is exploiting both old and new exploits, below is list of vulnerabilities exploited:
- CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution Vulnerability
- CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability
- CVE-2022-26258: D-Link Remote Command Execution Vulnerability
- CVE-2022-28958: D-Link Remote Command Execution Vulnerability
Threat actors explored the four D-Link vulnerabilities to gain remote code execution and download a MooBot downloader from 159.203.15[.]179.
“Upon execution, the binary file prints get haxored! to the console, spawns processes with random names and wipes out the executable file.” reads the analysis published by Unit 42. “As a variant, MooBot inherits Mirai’s most significant feature – a data section with embedded default login credentials and botnet configuration – but instead of using Mirai’s encryption key, 0xDEADBEEF, MooBot encrypts its data with 0x22.”
At the time of the analysis, the C2 server was offline. The analysis of the code revealed that the MooBot bot will also send heartbeat messages to the C2 server and parse commands from C2 to start a DDoS attack on a specific IP address and port number.
Researchers strongly recommend users of D-Link routers of applying patches and upgrades when possible. For users that suspect their router has been compromised, the experts recommend resetting the device, changing the admin password, and then installing the latest updates.
“The vulnerabilities mentioned above have low attack complexity but critical security impact that can lead to remote code execution. Once the attacker gains control in this manner, they could take advantage by including the newly compromised devices into their botnet to conduct further attacks such as DDoS.” concludes the report.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, D-Link)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/135414/malware/moobot-botnet-targets-d-link.html