ZeroHour
Security Affairspublished ()ingested @securityaffairs

IoT under siege: The return of the Mirai

criticalExploit / PoCimportance 60CVE-2024-12856

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-12856
OS Command Injection in Four-Faith F3x24/F3x36 Routers

Four-Faith industrial router models F3x24 and F3x36 running firmware version 2.0 are vulnerable to OS command injection (CWE-78) through the apply.cgi interface when an attacker modifies the system time over HTTP. The flaw is technically authenticated (CVSS 3.1: 7.2, network-adjacent-remote with high privileges required), but the same firmware ships with default credentials, so any device where defaults were not changed is effectively exposed to unauthenticated remote OS command execution. A successful attacker can run arbitrary commands on the router, gaining full device compromise that can be used for further access or recruitment into botnets. Four-Faith deployments — typically industrial and remote-connectivity routers — are affected, with at least 15,000 routers exposed to the internet and many retaining default credentials. Exploitation is confirmed in the wild: a Mirai botnet variant has weaponized the flaw for DDoS attacks, and the RondoDox botnet is also targeting it, consistent with a high EPSS score (84.2% probability of exploitation within 30 days, 100th percentile).

Do: Update F3x24/F3x36 devices to the latest firmware available from Four-Faith and verify apply.cgi handling is fixed; as an immediate mitigation, change default administrator credentials and restrict HTTP management access to trusted networks. Check devices for signs of botnet infection (unexpected outbound traffic or Crontab/persistence changes) and prioritize patching given confirmed in-the-wild exploitation by Mirai and RondoDox botnets.

7.284% PoC ×2
  • Four-Faith F3x24 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
  • Four-Faith F3x36 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
large≈15,000+ internet-exposed routers (headline scan count; total deployments likely higher)

Indicators of compromiseAll →

TypeIndicatorContext
domaincross-compiling.orgemboy connects to its C2 by resolving random domains (e.g., cross-compiling[.]org , furry-femboys[.]top ) via public DNS (1.1.1.1, 8.8.8.8)
domainfurry-femboys.topby resolving random domains (e.g., cross-compiling[.]org , furry-femboys[.]top ) via public DNS (1.1.1.1, 8.8.8.8) to evade local filter
ipv41.1.1.1oss-compiling[.]org , furry-femboys[.]top ) via public DNS (1.1.1.1, 8.8.8.8) to evade local filtering. It scans 15 ports to es
ipv48.8.8.8ling[.]org , furry-femboys[.]top ) via public DNS (1.1.1.1, 8.8.8.8) to evade local filtering. It scans 15 ports to establish c
Full article573 words · extracted from securityaffairs.com · click to collapse

Mirai-based Gayfemboy botnet resurfaces, evolving to target systems worldwide; Fortinet researchers provided details about the new campaign.

FortiGuard Labs researchers tracked a new Gayfemboy botnet campaign, the malware exploits known flaws in DrayTek, TP-Link, Raisecom, and Cisco, showing evolved tactics and renewed activity.

The Gayfemboy botnet was first identified in February 2024, it borrows the code from the basic Mirai variant and integrates N-day and 0-day exploits.

By November 2024, Gayfemboy exploited 0-day vulnerabilities in Four-Faith industrial routers and Neterbit routers and Vimar smart home devices, with over 15,000 daily active nodes. Operators behind the botnet also launched DDoS attacks against researchers tracking it.

In January 2025, QiAnXin XLab experts observed the Gayfemboy delivering its bot by exploiting more than 20 vulnerabilities, they also attempted to exploit Telnet weak credentials. The researchers discovered that attackers targeted the zero-day vulnerability CVE-2024-12856 in Four-Faith industrial routers along with several unknown vulnerabilities affecting Neterbit and Vimar devices.

In July 2025, FortiGuard Labs found a Gayfemboy payload exploiting multiple device flaws. Attacks originated from IPs 87[.]121[.]84[.]34 and 220[.]158[.]234[.]135. The experts identified the downloader scripts for multiple devices targeted by the bot, including Asus, Vivo, Zyxel, and Realtek. The malicious code fetched malware and XMRig miners, with product names passed as parameters to Gayfemboy for execution.

“Gayfemboy employs its first layer of obfuscation during the file download stage. Unlike Mirai and Gafgyt variants, which typically use Linux architecture names as file extensions, Gayfemboy assigns distinct names to each architecture, avoiding predictable naming conventions.” reads the report published by Fortinet Labs.

The Gayfemboy botnet targets multiple countries, including Brazil, Mexico, the United States, Germany, France, Switzerland, Israel, and Vietnam. Experts observed victims in multiple sectors, such as Manufacturing, Technology, Construction, and Media or Communications.

Gayfemboy malware employs custom file naming to evade detection and obfuscates binaries with a modified UPX header. The malware kills rival malware processes. It has four core modules: Monitor (anti-analysis, persistence, sandbox evasion, process-killing), Watchdog (ensures single instance, kills unresponsive copies), Attacker (DDoS and backdoor functions), and Killer (removes competing infections).

“Within the Monitor function, Gayfemboy includes two dedicated sub-functions: Self-Persistence and Sandbox Evasion. Self-Persistence ensures the malware remains active. If Gayfemboy detects that its process has been terminated, it automatically re-executes itself.” continues the report. “As part of its Sandbox Evasion technique, Gayfemboy introduces a deliberate delay of 50 nanoseconds. If executed in a sandbox environment that cannot accurately handle such a fine-grained delay, the timing function fails, causing the malware to misinterpret the result and initiate a fallback sleep of approximately 27 hours.”

Gayfemboy connects to its C2 by resolving random domains (e.g., cross-compiling[.]org, furry-femboys[.]top) via public DNS (1.1.1.1, 8.8.8.8) to evade local filtering. It scans 15 ports to establish communication and supports lightweight 4-byte commands (reset, sleep, info) plus extended commands like payload download, reverse shell, firewall rule changes, and launching DDoS. Self-protection includes clock-based sandbox checks and a remote ^kill^ command.

“While Gayfemboy inherits structural elements from Mirai, it introduces notable modifications that enhance both its complexity and ability to evade detection. This evolution reflects the increasing sophistication of modern malware and reinforces the need for proactive, intelligence-driven defense strategies.” concludes the report that includes Indicators of Compromise. “Staying ahead requires not only regular patching but also in-depth analysis and exposure of emerging threats to develop effective countermeasures and mitigate risk.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Gayfemboy botnet)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181480/cyber-crime/iot-under-siege-the-return-of-the-mirai-based-gayfemboy-botnet.html