Mirai V3G4 botnet exploits 13 flaws to target IoT devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2012-4869 | NVD description · AI analysis pending | — | 70% | — | — | — | |
| CVE-2014-9727 | NVD description · AI analysis pending | — | 72% | — | — | — | |
| CVE-2017-5173 | An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution. NVD description · AI analysis pending | 9.8 | 30% | PoC |
| — | |
| CVE-2019-15107 | Unauthenticated Command Injection RCE in Webmin <= 1.920 CVE-2019-15107 is a critical (CVSS 9.8) unauthenticated command injection (CWE-78) in Webmin versions 1.920 and earlier, located in the 'old' parameter of password_change.cgi. An attacker can trigger it by sending a crafted, unauthenticated request to password_change.cgi with shell metacharacters in that parameter, causing arbitrary commands to execute on the server. Because Webmin typically runs with elevated privileges, successful exploitation yields full control of the host, and the flaw has seen real-world use including ransomware operations. Any system running Webmin 1.920 or older is affected, and related reporting indicates backdoored Webmin versions were available for download for over a year, so compromised installs may not be obvious. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-03-25) with known ransomware use, EPSS puts the 30-day exploitation probability at 99.8%, multiple public PoCs exist, and the Roboto P2P botnet has been reported targeting Linux Webmin servers. Do: Upgrade Webmin to a version later than 1.920 per vendor instructions, which is CISA's required action for KEV listings. Because backdoored Webmin versions were reportedly distributed for over a year, also hunt for signs of compromise (unexpected processes, outbound connections, or a modified password_change.cgi) rather than only patching. Until updated, restrict access to the Webmin interface (default TCP port 10000) to trusted networks or place it behind a VPN. | 9.8 | 100% | KEV ransomware PoC ×5 |
| masson the order of 100,000+ internet-exposed Webmin servers | |
| CVE-2020-15415 | Unauthenticated OS Command Injection in DrayTek Vigor3900/2960/300B Routers DrayTek Vigor3900, Vigor2960, and Vigor300B routers running firmware before 1.5.1 contain an unauthenticated OS command injection flaw (CWE-78) in the cvmcfgupload handler of the web management interface (cgi-bin/mainfunction.cgi/cvmcfgupload), distinct from CVE-2020-14472. A remote attacker sends an upload request using the text/x-python-script content type with shell metacharacters embedded in the filename, which the device passes to a shell without sanitization, achieving arbitrary command execution. Because no credentials or user interaction are required, an internet-exposed management interface can be fully compromised, giving the attacker control of the router and a foothold into the network behind it. Any organization or site running one of these three Vigor models on pre-1.5.1 firmware is affected, especially where the web UI is reachable from the internet. Exploitation is confirmed: a public proof-of-concept exists, EPSS rates 30-day exploitation probability at 84.5% (100th percentile), CISA added the bug to the Known Exploited Vulnerabilities catalog on 2024-09-30, and recent reporting ties Mirai V3G4 botnet activity to campaigns exploiting a batch of 13 IoT flaws. Do: Upgrade Vigor3900, Vigor2960, and Vigor300B firmware to version 1.5.1 or later per DrayTek's instructions, consistent with the CISA KEV required action (apply vendor mitigations or discontinue use). Until patched, do not expose the web management interface to the internet (restrict to trusted management IPs or VPN access) and hunt for compromise indicators such as unexpected processes, altered configurations, or Mirai-like scanning traffic. Check access logs for requests to /cgi-bin/mainfunction.cgi/cvmcfgupload using the text/x-python-script content type with metacharacters in the filename. | 9.8 | 84% | KEV PoC |
| large≈100,000 internet-exposed Vigor3900/2960/300B devices (order-of-magnitude estimate) | |
| CVE-2020-8515 | Unauthenticated Command Injection RCE in DrayTek Vigor3900/2960/300B Routers CVE-2020-8515 is an unauthenticated OS command injection flaw (CWE-78) in the web management page of DrayTek Vigor3900, Vigor2960, and Vigor300B routers. An attacker can trigger it by sending crafted, unauthenticated HTTP requests to the router's management web interface, injecting shell metacharacters into commands executed by the device. Successful exploitation yields remote code execution on the router, allowing an attacker to install web shells, alter firewall/VPN settings, intercept traffic, or pivot into the protected network. Any organization running affected Vigor3900/2960/300B firmware with the management interface reachable from the internet is exposed; these models are commonly deployed as small-business and branch-office VPN gateways. The flaw is being actively exploited: CISA added it to the KEV on 2021-11-03 and EPSS assigns a 100% probability of exploitation within 30 days, though no public PoC is catalogued. Do: Upgrade Vigor3900, Vigor2960, and Vigor300B to firmware 1.5.1.1 or later per DrayTek's instructions, as required by the CISA KEV entry. Do not expose the web management page directly to the internet, and inspect internet-facing units for indicators of compromise such as unexpected web shell files (e.g., webs.php), unknown administrator accounts, or altered firewall/VPN settings. If compromise is confirmed, perform a factory reset and reflash clean firmware, then restore configurations from trusted backups. | 9.8 | 100% | KEV PoC |
| large≈10,000–100,000 internet-exposed Vigor routers (total Vigor installed base in the millions) | |
| CVE-2022-26134 | Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target. Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022… | |
| CVE-2022-36267 | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device. NVD description · AI analysis pending | 9.8 | 55% | PoC ×2 |
| — | |
| CVE-2022-4257 | A vulnerability was found in C-DATA Web Management System. A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-bin/jumpto.php of the component GET Parameter Handler. The manipulation of the argument hostname leads to argument injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214631. NVD description · AI analysis pending | 9.8 | 44% | PoC |
| — |
Full article546 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 16, 2023

During the second half of 2022, a variant of the Mirai bot, tracked as V3G4, targeted IoT devices by exploiting tens of flaws.
Palo Alto Networks Unit 42 researchers reported that a Mirai variant called V3G4 was attempting to exploit several flaws to infect IoT devices from July to December 2022.
Below is the list of vulnerabilities exploited by V3G4:
- CVE-2012-4869: FreePBX Elastix Remote Command Execution Vulnerability
- Gitorious Remote Command Execution Vulnerability
- CVE-2014-9727: FRITZ!Box Webcam Remote Command Execution Vulnerability
- Mitel AWC Remote Command Execution Vulnerability
- CVE-2017-5173: Geutebruck IP Cameras Remote Command Execution Vulnerability
- CVE-2019-15107: Webmin Command Injection Vulnerability
- Spree Commerce Arbitrary Command Execution Vulnerability
- FLIR Thermal Camera Remote Command Execution Vulnerability
- CVE-2020-8515: DrayTek Vigor Remote Command Execution Vulnerability
- CVE-2020-15415: DrayTek Vigor Remote Command Injection Vulnerability
- CVE-2022-36267: Airspan AirSpot Remote Command Execution Vulnerability
- CVE-2022-26134: Atlassian Confluence Remote Code Execution Vulnerability
- CVE-2022-4257: C-Data Web Management System Command Injection Vulnerability
The threat actors’ goal is to infect the largest number of systems as possible to compose a botnet that can be used to conduct multiple attacks, including DDoS attacks.
The researchers have observed three different Mirai V3G4 campaigns likely operated by the same threat actor for the following reasons:
- The hardcoded command and control (C2) domains among these three campaigns contain the same string (8xl9)
- The malware shell script downloaders are almost identical between the three campaigns
- The botnet client samples use the same XOR decryption key
- The botnet client samples use the same “stop list” (a list of target processes that the botnet client searches for and terminates)
- The botnet client samples use almost identical functions
The botnet exploited 13 vulnerabilities to achieve remote code execution on vulnerable devices. Upon successful exploitation, the malicious code executes wget and curl utilities to download Mirai bot from attackers’ infrastructure and then execute it.
Upon execution, the bot prints xXxSlicexXxxVEGA. to the console. The experts noticed that V3G4 also supports a function that makes sure only one instance of this malware is executing on the compromised device. If a botnet process already exists, the botnet client will and exit.
The botnet also attempts to terminate a list of processes, included in the hardcoded ‘stop list,’ by checking their names on the infected device.
Unlike most Mirai variants, the V3G4 variant uses different XOR encryption keys for string encryption.
The researchers also noticed that the bot samples from the three campaigns have minor differences. The original Mirai botnet sample spreads itself by brute-forcing weak telnet/SSH credentials, while other variants rely brute-force attacks and embedded exploits to spread.
However, bot samples discovered between September and December 2022 don’t contain the functions of vulnerability exploitation and brute force of credentials.
“The vulnerabilities mentioned above have less attack complexity than previously observed variants, but they maintain a critical security impact that can lead to remote code execution. Once the attacker gains control of a vulnerable device in this manner, they could take advantage by including the newly compromised devices in their botnet to conduct further attacks such as DDoS.” concludes the report. “Therefore, it is highly recommended that patches and updates are applied when possible.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, V3G4)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/142358/malware/mirai-v3g4-botnet.html