ZeroHour
The Recordpublished ()ingested

Russian security firm sinkholes part of the dangerous Meris DDoS botnet

mediumMalwareimportance 35CVE-2018-14847

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-14847
Directory Traversal in MikroTik RouterOS Winbox Interface (Unauthenticated File Read)

CVE-2018-14847 is a directory traversal (CWE-22) vulnerability in the Winbox interface of MikroTik RouterOS through version 6.42. An unauthenticated remote attacker can send crafted Winbox requests that traverse directories to read arbitrary files on the device, while authenticated attackers can also write arbitrary files. By reading files an attacker can retrieve sensitive device data such as stored credentials or configuration, and file write capability can support further compromise of the router. Any MikroTik router or device running RouterOS at or below 6.42 with the Winbox interface reachable is affected, which includes large numbers of internet-exposed edge and ISP devices. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-12-01), has multiple public PoCs, and compromised MikroTik routers have been used by threats such as Trickbot (as C2 proxies) and the Mēris botnet, with public scans reporting over 300,000 vulnerable devices.

Do: Apply MikroTik's updates per vendor instructions, moving RouterOS above version 6.42, prioritizing devices with Winbox reachable from untrusted networks. Until patched, restrict or disable Winbox access from WAN/untrusted interfaces to limit unauthenticated file reads. Given known botnet abuse of this flaw, check devices for signs of compromise and rotate credentials that may have been exposed via file reads.

9.196% KEV PoC ×7
  • mikrotik routeros through 6.42 (all versions at or below 6.42)
mass≈300,000+ internet-exposed MikroTik devices

Indicators of compromiseAll →

TypeIndicatorContext
domaincosmosentry.comasking for new instructions from an unregistered domain at cosmosentry[.]com . Seizing the operator's mistake, Rostelecom-Solar engine
Full article633 words · extracted from therecord.media · click to collapse

Rostelecom-Solar, the cybersecurity division of Russian telecom giant Rostelecom, said on Monday that it sinkholed a part of the Meris DDoS botnet after identifying a mistake from the malware's creators.

First spotted earlier this year, the Meris botnet is currently the largest DDoS botnet on the internet, with an estimated size of around 250,000 infected systems.

For the past few months, the botnet has been abused by a threat actor that has engaged in DDoS extortion attacks against internet service providers and financial entities across several countries, such as Russiathe UKthe US, and New Zealand.

The attacks have been brutal, with companies often going offline overwhelmed by the botnet's sheer power. As part of this ferocious campaign, Meris broke the record for the largest volumetric DDoS attack twice this year, once in June and then again in September.

Internet infrastructure firms like Cloudflare and Qrator Labs have analyzed the botnet following attacks on their customers and found that the vast majority of infected systems have been MikroTik networking equipment like routers, switches, and access points.

In a blog post last week, MikroTik said the attackers abused an old vulnerability (CVE-2018-14847) in its RouterOS to assemble their botnet using devices that haven't been updated by their owners.

Meris botnet operators make a mistake

But in research published on Monday, Rostelecom-Solar said that during routine analysis of this new threat, which has also been attacking some of its customers, its engineers found that some infected routers were reaching out and asking for new instructions from an unregistered domain at cosmosentry[.]com.

Seizing the operator's mistake, Rostelecom-Solar engineers said they registered this domain and converted it into a "sinkhole."

After days of tracking, researchers said they received pings from around 45,000 infected MikroTik devices, a number estimated to be around a fifth of the botnet's entire size.

"Unfortunately, we cannot take any active actions with devices under our control (we do not have the authority to do this)," the company said this week.

"At the moment, about 45,000 MikroTik devices turn to us as a sinkhole domain."

In case MikroTik router owners detect these suspicious connections to the cosmosentry[.]com, Rostelecom-Solar said they've set up a placeholder message informing them of who owns the domain and why their router is making the connection.

The Glupteba connection

Furthermore, researchers said they also identified clues in the Meris malware code that also provided an insight into how this botnet had been assembled.

Per the Rostelecom-Solar team, the Meris botnet appears to have been assembled via Glupteba, a malware strain targeting Windows computers, typically used as a loader for various other malware strains.

Researchers pointed to two 2020 reports from cyber-security firms Sophos [PDF] and Trend Micro, both of which documented a new Glupteba module at the time that was specialized in attacking MikroTik routers found on companies' internal networks via the CVE-2018-14847 vulnerability.

Similarities in the Meris code and the fact that many routers which pinged Rostelecom's sinkhole using internal IPs confirmed the company's theory that Meris was fully or partially assembled via the Glupteba malware.

However, it is currently unclear if the Glupteba gang built the Meris botnet themselves or if another group rented access to Glupteba-infected hosts to deploy the MikroTik module that eventually led to Meris' creation.

Rostelecom-Solar said it notified authorities about their findings. The report was shared with the National Coordination Center for Computer Incidents (NKTsKI), a CERT-like organization created by the Russian Federal Security Service (FSB) in 2018.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russian-security-firm-sinkholes-part-of-the-dangerous-meris-ddos-botnet