Mirai Variant MooBot Botnet Exploiting D
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-2051 | Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life. Do: Because the DIR-645 is end-of-life, CISA's required action is to disconnect it; replace the device where possible, or at minimum apply the latest available D-Link firmware for the DIR-645 and ensure the management/HNAP interface is not reachable from the internet (block or restrict remote administration on the WAN side). Check the device for signs of botnet infection, such as unexpected outbound traffic or unexpected HNAP POST/SOAP requests, and prioritize this fix given the 97.1% EPSS score and known in-the-wild exploitation. | — | 97% | KEV |
| largetens of thousands of internet-exposed devices (est.; far more DIR-645 units exist behind NAT given the product's broad consumer/SOHO distribution) | |
| CVE-2018-6530 | Unauthenticated OS Command Injection in D-Link DIR-860L/865L/868L/880L Routers CVE-2018-6530 is an unauthenticated OS command injection flaw (CWE-78) in the SOAP interface (soap.cgi, handled by soapcgi_main in the cgibin binary) of several D-Link routers. A remote attacker sends a crafted request to soap.cgi containing a malicious 'service' parameter, causing arbitrary OS commands to execute on the router with no credentials or user interaction required. Successful exploitation yields full command execution on the device, enabling takeover, credential theft, or recruitment into botnets. Affected users are anyone running a D-Link DIR-860L, DIR-865L, DIR-868L, or DIR-880L on firmware at or below the versions listed in the advisory. Exploitation is active in the wild: CISA added the flaw to the KEV catalog on 2022-09-08 with known ransomware use, the Mirai variant MooBot/Moobot has been exploiting vulnerable D-Link routers to build botnets, and EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile). Do: Apply the latest available firmware from D-Link — the vendor advisory states that the fix released under CVE-2018-20114 properly patches this vulnerability. Because all four affected models have reached end-of-life, CISA recommends disconnecting any affected device still in use if no supported firmware is available, and replacing it if it is internet-facing. As an interim mitigation, block or restrict WAN access to the router's web/SOAP (soap.cgi/HNAP) interface and check device logs for unexpected outbound connections indicative of MooBot/Mirai compromise. | 9.8 | 97% | KEV ransomware PoC |
| massorder of 100,000+ internet-exposed devices, with total installed units across the four consumer router models plausibly in the millions (estimate) | |
| CVE-2022-26258 | Unauthenticated Remote Command Execution in D-Link DIR-820L Router CVE-2022-26258 is an unauthenticated OS command injection (CWE-78) in D-Link DIR-820L router firmware, confirmed in version 1.05B03, reachable through the HTTP POST 'get set ccp' command interface. A remote attacker with no credentials and no user interaction can send a crafted HTTP POST request to this endpoint to execute arbitrary operating-system commands on the device. Successful exploitation yields full control of the router, providing a foothold for traffic interception, device enlistment into botnets, and lateral access to the home or small-office network behind it. Only users running the affected D-Link DIR-820L, an end-of-life consumer router, are affected, and no fixed firmware version is provided in the available data. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08 with a 92% EPSS score, and public reporting describes the Mirai-variant MooBot botnet targeting vulnerable D-Link devices. Do: Because the DIR-820L is end-of-life and CISA's required action is to disconnect it if still in use, replace or retire the router; check the model and firmware version on the device's status/admin page (1.05B03 is confirmed vulnerable). If replacement is not immediate, disconnect the device from the internet or restrict exposure with firewall rules so the HTTP management interface is not reachable by untrusted hosts, and watch for Mirai-variant (MooBot) botnet traffic patterns. No fixed firmware version is provided in the available data, so upgrading alone is not a documented remedy. | 9.8 | 92% | KEV PoC ×2 |
| large≈10,000–100,000 internet-exposed DIR-820L devices (order-of-magnitude estimate; a widely sold but end-of-life consumer router) | |
| CVE-2022-28958 | Rejected reason: DO NOT USE THIS CVE RECORD. Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. NVD description · AI analysis pending | — | — | — | — |
Full article316 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 07, 2022
A variant of the Mirai botnet known as MooBot is co-opting vulnerable D-Link devices into an army of denial-of-service bots by taking advantage of multiple exploits.
"If the devices are compromised, they will be fully controlled by attackers, who could utilize those devices to conduct further attacks such as distributed denial-of-service (DDoS) attacks," Palo Alto Networks Unit 42 said in a Tuesday report.
MooBot, first disclosed by Qihoo 360's Netlab team in September 2019, has previously targeted LILIN digital video recorders and Hikvision video surveillance products to expand its network.
In the latest wave of attacks discovered by Unit 42 in early August 2022, as many as four different flaws in D-Link devices, both old and new, have paved the way for the deployment of MooBot samples. These include -
- CVE-2015-2051 (CVSS score: 10.0) - D-Link HNAP SOAPAction Header Command Execution Vulnerability
- CVE-2018-6530 (CVSS score: 9.8) - D-Link SOAP Interface Remote Code Execution Vulnerability
- CVE-2022-26258 (CVSS score: 9.8) - D-Link Remote Command Execution Vulnerability, and
- CVE-2022-28958 (CVSS score: 9.8) - D-Link Remote Command Execution Vulnerability
Successful exploitation of the aforementioned flaws could lead to remote code execution and the retrieval of a MooBot payload from a remote host, which then parses instructions from a command-and-control (C2) server to launch a DDoS attack on a specific IP address and port number.
Customers of D-Link appliances are highly recommended to apply patches and upgrades released by the company to mitigate potential threats.
"The vulnerabilities [...] have low attack complexity but critical security impact that can lead to remote code execution," the researchers said. "Once the attacker gains control in this manner, they could take advantage by including the newly compromised devices into their botnet to conduct further attacks such as DDoS."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/09/mirai-variant-moobot-botnet-exploiting.html