ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Mirai-based Botnet Exploiting Zero-Day Bugs in Routers and NVRs for Massive DDoS Attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-47565
Authenticated OS Command Injection in QNAP VioStor NVR (QVR Firmware 4.x)

CVE-2023-47565 is an OS command injection vulnerability (CWE-78) affecting legacy QNAP VioStor NVR models running QVR Firmware 4.x, rated 8.8 (High) on the CVSS 3.1 scale. An authenticated user can send crafted input over the network that the device passes to the underlying operating system, triggering arbitrary command execution. Successful exploitation allows the attacker to run OS commands on the NVR, which typically means full compromise of the device for data access, lateral movement, or enrollment into botnets such as the Mirai-based InfectedSlurs campaign. Only organizations still operating legacy VioStor NVR hardware on QVR 4.x are affected; QNAP fixed the vulnerability in QVR Firmware 5.0.0 and later. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, EPSS assigns a 73.3% probability of exploitation within 30 days (99th percentile), and the InfectedSlurs botnet has been reported actively targeting it.

Do: Upgrade affected legacy VioStor NVRs to QVR Firmware 5.0.0 or later; per CISA's KEV required action, apply vendor mitigations or discontinue use of any unit that cannot be updated. Remove internet exposure of the NVR web interface where possible, verify the running QVR firmware version on each device, and hunt for signs of botnet infection (unusual outbound traffic or processes) given confirmed in-the-wild exploitation.

8.873% KEV
  • QNAP VioStor NVR (QVR Firmware) QVR Firmware 4.x on legacy VioStor NVR models; fixed in QVR Firmware 5.0.0 and later
large≈tens of thousands of internet-exposed legacy VioStor NVR devices (estimate)
CVE-2023-49897
OS Command Injection in FXC AE1021/AE1021PE Routers Exploited in the Wild

An OS command injection flaw (CWE-78) exists in FXC AE1021 and AE1021PE router firmware versions 2.0.9 and earlier. An attacker who is able to log in to the device can submit crafted input that the firmware passes to the underlying operating system, causing arbitrary OS commands to be executed. Successful exploitation yields arbitrary command execution on the router with high impact across confidentiality, integrity, and availability (CVSS 3.1 8.8), effectively giving the attacker control of the device. Any user or organization running AE1021 or AE1021PE firmware 2.0.9 or earlier is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, and public Akamai research ties it to a Mirai-based botnet campaign exploiting these routers for DDoS activity, with a 50.4% EPSS probability of exploitation over the next 30 days (99th percentile).

Do: Upgrade AE1021 and AE1021PE devices to the latest FXC firmware (any version newer than 2.0.9), per the vendor advisory and the CISA KEV required action; if patching is not possible, discontinue use of the product or restrict its management interface to trusted networks with strong login credentials. Review devices for signs of compromise, such as unexpected outbound connections or changed credentials, since a Mirai-based botnet campaign has been observed exploiting these routers.

8.850% KEV PoC
  • FXC AE1021PE firmware 2.0.9 and earlier
  • FXC AE1021 firmware 2.0.9 and earlier
unknown precise count; plausibly on the order of tens of thousands of deployed units
Full article644 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 23, 2023Vulnerability / Cyber Threat

An active malware campaign is leveraging two zero-day vulnerabilities with remote code execution (RCE) functionality to rope routers and video recorders into a Mirai-based distributed denial-of-service (DDoS) botnet.

“The payload targets routers and network video recorder (NVR) devices with default admin credentials and installs Mirai variants when successful,” Akamai said in an advisory published this week.

Details of the flaws are currently under wraps to allow the two vendors to publish patches and prevent other threat actors from abusing them. The fixes for one of the vulnerabilities are expected to be shipped next month.

The attacks were first discovered by the web infrastructure and security company against its honeypots in late October 2023. The perpetrators of the attacks have not been identified as yet.

The botnet, which has been codenamed InfectedSlurs due to the use of racial and offensive language in the command-and-control (C2) servers and hard-coded strings, is a JenX Mirai malware variant that came to light in January 2018.

Akamai said it also identified additional malware samples that appeared to be linked to the hailBot Mirai variant, the latter of which emerged in September 2023, according to a recent analysis from NSFOCUS.

“The hailBot is developed based on Mirai source code, and its name is derived from the string information ‘hail china mainland’ output after running,” the Beijing-headquartered cybersecurity firm noted, detailing its ability to propagate via vulnerability exploitation and weak passwords.

The development comes as Akamai detailed a web shell called wso-ng, an “advanced iteration” of WSO (short for “web shell by oRb”) that integrates with legitimate tools like VirusTotal and SecurityTrails while stealthily concealing its login interface behind a 404 error page upon attempting to access it.

One of the notable reconnaissance capabilities of the web shell involves retrieving AWS metadata for subsequent lateral movement as well as searching for potential Redis database connections so as to obtain unauthorized access to sensitive application data.

“Web shells allow attackers to run commands on servers to steal data or use the server as a launch pad for other activities like credential theft, lateral movement, deployment of additional payloads, or hands-on-keyboard activity, while allowing attackers to persist in an affected organization,” Microsoft said back in 2021.

The use of off-the-shelf web shells is also seen as an attempt by threat actors to challenge attribution efforts and fly under the radar, a key hallmark of cyber espionage groups that specialize in intelligence gathering.

Another common tactic adopted by attackers is the use of compromised-but-legitimate domains for C2 purposes and malware distribution.

In August 2023, Infoblox disclosed a widespread attack involving compromised WordPress websites that conditionally redirect visitors to intermediary C2 and dictionary domain generation algorithm (DDGA) domains. The activity has been attributed to a threat actor named VexTrio.

Update

Akamai is warning that the threat actors behind the InfectedSlurs botnet are actively exploiting security flaws in Future X Communications (FXC) AE1021 and AE1021PE outlet wall routers (CVE-2023-49897, CVSS score: 8.8) and QNAP VioStor NVR appliances (CVE-2023-47565, CVSS score: 8.8) to marshall the devices to the DDoS attack swarm.

Both the vulnerabilities are operating system command injection bugs that could allow an authenticated attacker to achieve code execution.

"Internet of Things (IoT)-targeted campaigns result in countless instances in which everyday consumer devices are unwittingly enlisted in a number of malicious efforts," Akamai researchers said, urging users to change default passwords on devices during initial setup.

"DDoS botnets and cryptomining schemes are just some of the potential outcomes that can happen completely unbeknownst to the consumer whose device is affected. In some cases, the user may not even know the credentials could be changed on these devices at all."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/11/mirai-based-botnet-exploiting-zero-day.html