ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

New Mirai Botnet Exploits Zero

criticalMalwareimportance 60CVE-2024-12856

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-12856
OS Command Injection in Four-Faith F3x24/F3x36 Routers

Four-Faith industrial router models F3x24 and F3x36 running firmware version 2.0 are vulnerable to OS command injection (CWE-78) through the apply.cgi interface when an attacker modifies the system time over HTTP. The flaw is technically authenticated (CVSS 3.1: 7.2, network-adjacent-remote with high privileges required), but the same firmware ships with default credentials, so any device where defaults were not changed is effectively exposed to unauthenticated remote OS command execution. A successful attacker can run arbitrary commands on the router, gaining full device compromise that can be used for further access or recruitment into botnets. Four-Faith deployments — typically industrial and remote-connectivity routers — are affected, with at least 15,000 routers exposed to the internet and many retaining default credentials. Exploitation is confirmed in the wild: a Mirai botnet variant has weaponized the flaw for DDoS attacks, and the RondoDox botnet is also targeting it, consistent with a high EPSS score (84.2% probability of exploitation within 30 days, 100th percentile).

Do: Update F3x24/F3x36 devices to the latest firmware available from Four-Faith and verify apply.cgi handling is fixed; as an immediate mitigation, change default administrator credentials and restrict HTTP management access to trusted networks. Check devices for signs of botnet infection (unexpected outbound traffic or Crontab/persistence changes) and prioritize patching given confirmed in-the-wild exploitation by Mirai and RondoDox botnets.

7.284% PoC ×2
  • Four-Faith F3x24 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
  • Four-Faith F3x36 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
large≈15,000+ internet-exposed routers (headline scan count; total deployments likely higher)
Full article346 words · extracted from infosecurity-magazine.com · click to collapse

Security researchers have uncovered a new Mirai-based botnet that uses zero-day exploits for industrial routers and smart home devices to spread.

The offensively named “gayfemboy” botnet was first discovered by Chinese research outfit Qi'anxin XLab back in February 2024. Yet while its early iterations were unremarkable versions of Mirai, its developers have since ramped up their efforts, incorporating n-day and zero-day vulnerability exploitation to help it expand.

These included a zero-day bug in Four-Faith industrial routers (CVE-2024-12856) and previously unseen vulnerabilities in Neterbit routers and Vimar smart home devices, which have yet to be assigned CVEs.

Overall, the botnet uses more than 20 vulnerabilities and weak Telnet passwords to spread, according to XLab. The firm claimed to have observed around 15,000 active IPs located mainly in China, Russia, the US, Iran and Turkey.

Read more on Mirai botnets: New Mirai Variant Campaigns are Targeting IoT Devices

The botnet has been launching DDoS attacks intermittently since February 2024, with activity at its peak to date in October and November last year. Hundreds of targets from various sectors are apparently attacked every day – mainly in China, the US, Germany, the UK and Singapore.

In fact, the botnet herders turned the tool on XLab, after it registered some command-and-control (C2) domains names in order to conduct closer analysis.

“We resolved the registered domain name to our cloud vendor’s VPS. Ater discovering this, the owner began to regularly launch DDoS attacks on our registered domain name, with each attack lasting 10 to 30 seconds,” XLab said.

“After the cloud vendor discovered that our VPS was attacked, it would immediately black hole our VPS traffic for more than 24 hours, which would cause our VPS to be unable to provide services and be inaccessible (our VPS was killed by the cloud vendor before it was killed by [the botnet], as this is the cloud vendor’s service policy). Once the VPS service was restored, it attacked again.”

As the researchers did not have any DDoS mitigation service protecting them, they were ultimately forced to stop resolving the C2 domain name.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/mirai-botnet-zerodays-routers/