ZeroHour
The Recordpublished ()ingested

New Mirai botnet variant has been very busy, researchers say

criticalMalwareimportance 60CVE-2022-26134

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-26134
Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center

Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target.

Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections.

9.8100% KEV ransomware PoC ×2
  • Atlassian Confluence Server
  • Atlassian Confluence Data Center
largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022…
Full article432 words · extracted from therecord.media · click to collapse

Researchers have discovered a new variant of the infamous Mirai malware that compromises smart devices and adds them to a botnet. 

Called V3G4, the variant exploits 13 known vulnerabilities, according to research by Palo Alto Networks’ Unit 42. Mirai typically allows for full control of devices, adding them to its network of remotely controlled bots used to launch distributed denial-of-service (DDoS) attacks.

Mirai primarily targets online consumer devices such as internet protocol cameras and home routers.

The botnet was first found in August 2016 and has been used in some of the largest and most disruptive DDoS attacks, including the cyberattack on security journalist Brian Krebs’ website and an attack on French web host OVH.

Unit 42 tracked the new variant from July until December 2022. The 13 vulnerabilities cited include the widely discussed Atlassian unauthenticated remote code execution vulnerability — CVE-2022-26134 — and a bug in Mitel audio, web and video conferencing products.

The vulnerabilities targeted by V3G4 have less complexity than previously observed variants, according to the research, but they are nonetheless significant as exploitation can lead to remote code execution.

Mirai was also responsible for a 2016 DDoS attack on Domain Name System (DNS) provider Dyn, which involved about 100,000 infected devices. As a result, major internet platforms and services were unavailable to users in Europe and North America. 

Paras Jha, owner of a DDoS mitigation service ProTraf Solutions and the company’s co-founder, Josiah White, are believed to be behind the Mirai botnet.

The new stuff

Like the original version, V3G4 targets exposed servers and networking devices running Linux. The most significant feature the new variant inherited from the original Mirai is a data section that assists in brute force attacks, when hackers try to guess passwords, encryption keys or a passphrase. 

It also has a function that ensures only one instance of the malware is executing on the infected device.

Researchers also noticed that the malware samples from the three campaigns they observed between July and December are slightly different. The original Mirai botnet sample spread itself by brute-forcing weak credentials telnet or Secure Shell — two popular protocols that help computers communicate — whereas the new variant uses both brute-force and embedded exploits to spread themselves.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/new-mirai-botnet-variant-has-been-very-busy-researchers-say