ZeroHour
Security Affairspublished ()ingested @securityaffairs

Gayfemboy Botnet targets Four

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35394
Remote Code Execution via Memory Corruption in Realtek Jungle SDK

Realtek's Jungle SDK, a software development kit used to build firmware for a wide range of consumer and small-office networking devices (most notably routers), contains multiple memory corruption vulnerabilities that can be triggered remotely over the network; public disclosure tied the flaws to unauthenticated network-facing components bundled with the SDK, such as its UPnP and DHCP handling. An attacker who sends crafted packets to a vulnerable device can corrupt memory and, per the associated weakness types (CWE-78 command injection, CWE-138 improper neutralization), end up executing arbitrary code or operating-system commands with the privileges of the vulnerable service, effectively taking over the device. Because the SDK is licensed into many vendors' products rather than sold as a standalone application, exposure spans numerous router and embedded-device vendors, and end users may not even know their device relies on it. Exact affected SDK version ranges and per-vendor firmware lists were not specified in the available data, so defenders should rely on the latest vendor advisories. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-12-10, indicating confirmed exploitation in the wild; ransomware use is unknown and no public proof-of-concept is flagged in the available data.

Do: Per CISA's required action, apply firmware updates per your device vendor's instructions, since patches are distributed by the vendors that build on the SDK rather than by Realtek directly. Identify whether your router or embedded device uses Realtek Jungle SDK-based firmware (check the vendor's model/advisory pages) and prioritize updating internet-facing devices. Where patched firmware is not yet available, restrict direct internet exposure (firewall the WAN side) and disable or limit UPnP/DHCP-related exposed services if the vendor supports doing so, while monitoring vendor advisories.

9.8100% KEV PoC
  • Realtek Jungle Software Development Kit (SDK)
mass≈ millions of devices (SDK embedded in consumer router/IoT firmware across many vendors; at least ~100,000 likely internet-exposed)
CVE-2024-12856
OS Command Injection in Four-Faith F3x24/F3x36 Routers

Four-Faith industrial router models F3x24 and F3x36 running firmware version 2.0 are vulnerable to OS command injection (CWE-78) through the apply.cgi interface when an attacker modifies the system time over HTTP. The flaw is technically authenticated (CVSS 3.1: 7.2, network-adjacent-remote with high privileges required), but the same firmware ships with default credentials, so any device where defaults were not changed is effectively exposed to unauthenticated remote OS command execution. A successful attacker can run arbitrary commands on the router, gaining full device compromise that can be used for further access or recruitment into botnets. Four-Faith deployments — typically industrial and remote-connectivity routers — are affected, with at least 15,000 routers exposed to the internet and many retaining default credentials. Exploitation is confirmed in the wild: a Mirai botnet variant has weaponized the flaw for DDoS attacks, and the RondoDox botnet is also targeting it, consistent with a high EPSS score (84.2% probability of exploitation within 30 days, 100th percentile).

Do: Update F3x24/F3x36 devices to the latest firmware available from Four-Faith and verify apply.cgi handling is fixed; as an immediate mitigation, change default administrator credentials and restrict HTTP management access to trusted networks. Check devices for signs of botnet infection (unexpected outbound traffic or Crontab/persistence changes) and prioritize patching given confirmed in-the-wild exploitation by Mirai and RondoDox botnets.

7.284% PoC ×2
  • Four-Faith F3x24 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
  • Four-Faith F3x36 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
large≈15,000+ internet-exposed routers (headline scan count; total deployments likely higher)
CVE-2024-8957
OS Command Injection in PTZOptics PT30X-SDI/NDI Cameras Enables Chained RCE

PTZOptics PT30X-SDI and PT30X-NDI-XX-G2 cameras running firmware before 6.3.40 fail to sufficiently validate the ntp_addr configuration value, enabling an OS command injection flaw (CWE-78) that triggers when the camera's ntp_client is started. On its own the flaw requires high-privileged access, consistent with its CVSS 3.1 base score of 7.2, but when chained with CVE-2024-8956 it can be reached by a remote, unauthenticated attacker. Successful exploitation yields arbitrary OS command execution on the camera with high impact to confidentiality, integrity, and availability. Any organization running affected PT30X-series firmware is exposed, with the greatest risk to cameras that are directly reachable from the internet. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-04, indicating in-the-wild exploitation, and a public GreyNoise write-up documents the 0-day RCE alongside an EPSS exploitation probability of 81%.

Do: Upgrade PT30X-SDI and PT30X-NDI-XX-G2 cameras to firmware 6.3.40 or later per vendor instructions, or apply vendor mitigations or discontinue use per CISA's KEV required action. Audit devices for internet exposure (port forwards, NAT rules, cloud relay access) and restrict management and NTP-related interfaces to trusted networks. Ensure CVE-2024-8956 is also remediated, since chaining it with this bug is what enables unauthenticated remote command execution.

7.281% KEV PoC
  • PTZOptics PT30X-SDI camera firmware all versions before 6.3.40
  • PTZOptics PT30X-NDI-XX-G2 camera firmware all versions before 6.3.40
moderatelikely tens of thousands of PT30X-series cameras deployed worldwide, with only a subset (low thousands or fewer) directly internet-exposed
Full article530 words · extracted from securityaffairs.com · click to collapse

Gayfemboy, a Mirai botnet variant, has been exploiting a flaw in Four-Faith industrial routers to launch DDoS attacks since November 2024.

The Gayfemboy botnet was first identified in February 2024, it borrows the code from the basic Mirai variant and now integrates N-day and 0-day exploits.

By November 2024, Gayfemboy exploited 0-day vulnerabilities in Four-Faith industrial routers and Neterbit routers and Vimar smart home devices, with over 15,000 daily active nodes. Operators behind the botnet also launched DDoS attacks against researchers tracking it.

QiAnXin XLab experts observed the Gayfemboy delivering its bot by exploiting more than 20 vulnerabilities, they also attempted to exploit Telnet weak credentials. The researchers discovered that attackers targeted the zero-day vulnerability CVE-2024-12856 in Four-Faith industrial routers along with several unknown vulnerabilities affecting Neterbit and Vimar devices.

Gayfemboy exploits various vulnerabilities, including CVE-2013-3307, CVE-2021-35394, CVE-2024-8957, and others in DVRs, routers, and security appliances.

Most of the infections are in China, the United States, Iran, Russia, and Turkey.

“When Gayfemboy bots connect to the C2, they carry grouping information used to identify and organize infected devices, enabling attackers to efficiently manage and control the large botnet. This grouping information typically includes key identifiers, such as the device’s operating system type or other identifying details.” reads the report published by QiAnXin XLab. “Many attackers also prefer to use the infection method as an identifier. Gayfemboy’s grouping information is based on device details. The main infected devices are as follows:

GroupCount of Bot IPMethod of InfectionAffected Device
adtran2707UnknownUnknown
asus2080NDAYASUS Router
bdvr71461NDAYKguard DVR
peeplink1422UnknownNeterbit、LTE、CPE、NR5G Router
faith25900DAY(CVE-2024-12856)Four-Faith Industrial Router
vimar7442UnknownVimar Smart Home Device

The Gayfemboy botnet has been launching DDoS attacks against hundreds of global targets since February 2024, with activity peaking in October and November. Key targets include China, the U.S., Germany, and the U.K.

The botnet launched 10–30 second DDoS attacks on domains registered for analysis, targeting a VPS hosted by a cloud provider. Attacks triggered blackholing of VPS traffic for over 24 hours. With no DDoS protection, the team stopped resolving the domains. Traffic peaked at 100GB, per provider estimates.

The botnet is based on Mirai, the analysis of the code revealed it includes plaintext strings and a custom “gayfemboy” registration packet. The author added new commands and a PID-hiding function. Despite its evolution, its plaintext strings and unchanged output message, “we gone now\n,” highlight lax protection efforts.

“DDoS (Distributed Denial of Service) is a highly reusable and relatively low-cost cyberattack weapon. It can launch large-scale traffic attacks instantly using distributed botnets, malicious tools, or amplification techniques, depleting, disabling, or interrupting the target network’s resources. As a result, DDoS has become one of the most common and destructive forms of cyberattacks.” concludes the report that includes Indicators of Compromise (IoCs). “Its attack modes are diverse, attack paths are highly concealed, and it can employ continuously evolving strategies and techniques to conduct precise strikes against various industries and systems, posing a significant threat to enterprises, government organizations, and individual users.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, botnet)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172805/malware/gayfemboy-mirai-botnet-four-faith-flaw.html