Hoaxcalls Botnet expands the target list and adds new DDoS capabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-5722 | Unauthenticated SQL Injection to Root RCE in Grandstream UCM6200 Series IP PBX CVE-2020-5722 is an unauthenticated SQL injection (CWE-89) in the HTTP interface of the Grandstream UCM6200 series IP PBX, triggered by sending a crafted HTTP request to the appliance's web service. On firmware versions before 1.0.19.20 an attacker can abuse it to execute arbitrary shell commands as root on the appliance, and on versions before 1.0.20.17 it can also be used to inject HTML into the device's password recovery emails. Any organization running UCM6200-series firmware prior to 1.0.20.17 is affected, with internet-exposed PBX appliances at the greatest risk. The flaw carries a critical CVSS 3.1 score of 9.8 and a top-percentile EPSS probability (84.4%) of exploitation within 30 days; public proof-of-concept exploits exist, CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28, and related reporting on the Hoaxcalls botnet expanding its target list is consistent with in-the-wild abuse of these devices. Do: Upgrade UCM6200-series firmware to version 1.0.20.17 or later per Grandstream's instructions, which addresses both impact branches; devices on versions before 1.0.19.20 are exposed to unauthenticated root command execution and should be patched immediately. Until patched, restrict the appliance's HTTP interface to trusted management networks and review internet-exposed units for signs of compromise, since CISA has confirmed exploitation. | 9.8 | 84% | KEV PoC ×3 |
| large≈10,000–100,000 internet-exposed UCM6200 appliances (order-of-magnitude estimate) | |
| CVE-2020-8515 | Unauthenticated Command Injection RCE in DrayTek Vigor3900/2960/300B Routers CVE-2020-8515 is an unauthenticated OS command injection flaw (CWE-78) in the web management page of DrayTek Vigor3900, Vigor2960, and Vigor300B routers. An attacker can trigger it by sending crafted, unauthenticated HTTP requests to the router's management web interface, injecting shell metacharacters into commands executed by the device. Successful exploitation yields remote code execution on the router, allowing an attacker to install web shells, alter firewall/VPN settings, intercept traffic, or pivot into the protected network. Any organization running affected Vigor3900/2960/300B firmware with the management interface reachable from the internet is exposed; these models are commonly deployed as small-business and branch-office VPN gateways. The flaw is being actively exploited: CISA added it to the KEV on 2021-11-03 and EPSS assigns a 100% probability of exploitation within 30 days, though no public PoC is catalogued. Do: Upgrade Vigor3900, Vigor2960, and Vigor300B to firmware 1.5.1.1 or later per DrayTek's instructions, as required by the CISA KEV entry. Do not expose the web management page directly to the internet, and inspect internet-facing units for indicators of compromise such as unexpected web shell files (e.g., webs.php), unknown administrator accounts, or altered firewall/VPN settings. If compromise is confirmed, perform a factory reset and reflash clean firmware, then restore configurations from trusted backups. | 9.8 | 100% | KEV PoC |
| large≈10,000–100,000 internet-exposed Vigor routers (total Vigor installed base in the millions) |
Full article534 words · extracted from securityaffairs.com · click to collapse

The Hoaxcalls IoT botnet expanded the list of targeted devices and has added new distributed denial of service (DDoS) capabilities.
DDoS protection services provider Radware warns the Hoaxcalls Internet of Things (IoT) botnet has expanded the list of targeted devices, the experts also noticed that the operators implemented new distributed denial of service (DDoS) capabilities.
The Hoaxcalls was first spotted in April by researchers from Palo Alto Networks, it borrows the code from Tsunami and Gafgyt botnets and it is targeting CVE-2020-5722 and CVE-2020-8515 flaws respectively affecting Grandstream UCM6200 series devices and Draytek Vigor routers.
Both vulnerabilities have been rated as critical severity (i.e CVSS v3.1 score of 9.8 out of 10) because they are easy to exploit.
The botnet was initially designed to launch DDoS attacks using UDP, DNS and HEX floods.
Now security researchers from Radware reported having discovered a new version of the Hoaxcalls botnet that is targeting an unpatched issue in the ZyXEL Cloud CNM SecuManager. Experts also noticed that the new variant implements 16 new DDoS capabilities.
“On April 20th, 2020, Radware Researchers discovered a new variant of the Hoaxcalls Botnet spreading via an unpatched vulnerability impacting ZyXEL Cloud CNM SecuManager.” reads the report published by Radware. “The series of vulnerabilities impacting ZyXEL were published in full disclosure by Pierre Kim on March 9th, 2020. In addition to a new vector of propagation, the Hoaxcall Botnet also added 16 DDoS attack vectors in the new sample.”
The campaigns observed by Radware employed a number of variants
using different combinations of propagation exploits and DDoS attack vectors. Experts speculate that the threat actor behind these campaigns focused on finding and leveraging new exploits to build a DDoS botnet.
On April 20, experts uncovered a powerful variant of the botnet that was spreading from a single server, they also revealed that the number of hosting servers now exceeds 75.
“A significant increase in attack capabilities compared to the previous sample. Samples discovered by Radware can be found on URLhaus. This specific variant has only been seen propagating via the GrandStream UCM SQL injection vulnerability CVE-2020-5722. In the first 48 hours of discovery, our sensors recorded 15 unique IP addresses spreading malware from a server hosted at 176.123.3.96. Today the number of malware hosting servers has grown to over 75.” continues the report. “Upon initial inspection, the sample appeared to be related to Tsunami, but when reanalyzed at a later date, the sample returned a closer relation to Hoaxcalls.”
The latest variant discovered by the experts and tracked as XTC expands the list of targeted devices by including the exploit for the issue in the ZyXEL Cloud CNM SecuManager.
“The campaigns performed by the actor or group behind XTC and Hoaxcalls include several variants using different combinations of propagation exploits and DDoS attack vectors.” Radware concludes. “It is our opinion that the group behind this campaign is dedicated to finding and leveraging new exploits for the purpose of building a botnet that can be leveraged for large scale DDoS attacks,”
Please give me your vote for European Cybersecurity Blogger Awards – VOTE FOR YOUR WINNERS
https://docs.google.com/forms/d/e/1FAIpQLSe8AkYMfAAwJ4JZzYRm8GfsJCDON8q83C9_wu5u10sNAt_CcA/viewform
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Hoaxcalls, IoT botnet)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/102202/malware/hoaxcalls-botnet-new-variant.html