ZeroHour
The Recordpublished ()ingested

New Mirai variant adds stealth capabilities to notorious botnet code

highMalware exploited in the wildimportance 60
AI summary · glm-5.3-flash

FortiGuard Labs reports new Mirai-derived botnet Evooo1Bot actively exploits unpatched routers and edge devices, adding encrypted C2, stealthy SSH scanning, and proxying.

FortiGuard Labs has identified Evooo1Bot, a previously undocumented Linux malware based on the Mirai botnet code, which has been actively exploiting unpatched vulnerabilities in internet-facing hardware for at least a month. Targeted devices include routers and edge hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare, with telemetry showing activity in North and South America, Europe, India, China and Japan. Beyond Mirai's usual DDoS functions, the variant adds encrypted C2 communications, a honeypot-aware SSH scanner, a sniffer for unchanged default credentials, and abuse of the SOCKS protocol to turn compromised devices into persistent proxies for concealing origin and pivoting into internal networks.

  • Actively exploits unpatched Alcatel, D-Link, Netgear, Tenda and other devices
  • Encrypted C2 and honeypot detection exceed the baseline of Mirai derivatives
  • SOCKS proxy abuse hides attacker origin and enables internal network pivoting
  • Sniffer harvests devices still using factory default credentials
  • Mirai descendants Aisuru and KimWolf were targeted by law enforcement in March
Full article389 words · extracted from therecord.media · click to collapse

Malware that adds multiple capabilities to the infamous Mirai botnet code has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, researchers said Thursday.

Dubbed Evooo1Bot, the Linux-based malware targets routers and other hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare, according to researchers at FortiGuard Labs. 

Unpatched bugs in those devices allow Evooo1Bot to spread and carry out potential malicious activity, the researchers said. Evooo1Bot appears to be previously undocumented, they said.

The report does not specify how many devices have been compromised worldwide, but the company’s telemetry shows activity concentrated in North America, South America, Europe, India, China and Japan.

Beyond Mirai’s usual distributed denial-of-service (DDoS) functions, Evooo1Bot’s features include encrypted communications with command-and-control servers; a scanner that looks for Secure Shell (SSH) code and skips devices clearly set up as honeypots for malicious traffic; and a “sniffer” that looks for default access credentials that haven’t been changed since a device was put into service.

“These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” FortiGuard Labs said.

The malware also abuses the widely used SOCKS protocol that allows devices to connect with servers through a proxy. That capability “is arguably the most operationally significant,” FortiGuard Labs said. “By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure.”

The source code for Mirai was publicly released in 2016, and in the decade since, it has served as the basis for numerous variants that have drawn the attention of law enforcement agencies and cybersecurity specialists. 

Descendants such as Aisuru and KimWolf were targeted by agencies from the U.S., Canada and Germany in March. A Canadian man was charged in May with running KimWolf.

No previous article

No new articles

Joe Warminsky

has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code