ZeroHour
Security Affairspublished ()ingested @securityaffairs

New Mirai botnet variant Murdoc Botnet targets AVTECH IP cameras and Huawei HG532 routers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-17215
Huawei HG532 with some customized versions has a remote code execution vulnerability.

Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.

NVD description · AI analysis pending
8.878%
  • huawei hg532 firmware
CVE-2021-35394
Remote Code Execution via Memory Corruption in Realtek Jungle SDK

Realtek's Jungle SDK, a software development kit used to build firmware for a wide range of consumer and small-office networking devices (most notably routers), contains multiple memory corruption vulnerabilities that can be triggered remotely over the network; public disclosure tied the flaws to unauthenticated network-facing components bundled with the SDK, such as its UPnP and DHCP handling. An attacker who sends crafted packets to a vulnerable device can corrupt memory and, per the associated weakness types (CWE-78 command injection, CWE-138 improper neutralization), end up executing arbitrary code or operating-system commands with the privileges of the vulnerable service, effectively taking over the device. Because the SDK is licensed into many vendors' products rather than sold as a standalone application, exposure spans numerous router and embedded-device vendors, and end users may not even know their device relies on it. Exact affected SDK version ranges and per-vendor firmware lists were not specified in the available data, so defenders should rely on the latest vendor advisories. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-12-10, indicating confirmed exploitation in the wild; ransomware use is unknown and no public proof-of-concept is flagged in the available data.

Do: Per CISA's required action, apply firmware updates per your device vendor's instructions, since patches are distributed by the vendors that build on the SDK rather than by Realtek directly. Identify whether your router or embedded device uses Realtek Jungle SDK-based firmware (check the vendor's model/advisory pages) and prioritize updating internet-facing devices. Where patched firmware is not yet available, restrict direct internet exposure (firewall the WAN side) and disable or limit UPnP/DHCP-related exposed services if the vendor supports doing so, while monitoring vendor advisories.

9.8100% KEV PoC
  • Realtek Jungle Software Development Kit (SDK)
mass≈ millions of devices (SDK embedded in consumer router/IoT firmware across many vendors; at least ~100,000 likely internet-exposed)
CVE-2024-12856
OS Command Injection in Four-Faith F3x24/F3x36 Routers

Four-Faith industrial router models F3x24 and F3x36 running firmware version 2.0 are vulnerable to OS command injection (CWE-78) through the apply.cgi interface when an attacker modifies the system time over HTTP. The flaw is technically authenticated (CVSS 3.1: 7.2, network-adjacent-remote with high privileges required), but the same firmware ships with default credentials, so any device where defaults were not changed is effectively exposed to unauthenticated remote OS command execution. A successful attacker can run arbitrary commands on the router, gaining full device compromise that can be used for further access or recruitment into botnets. Four-Faith deployments — typically industrial and remote-connectivity routers — are affected, with at least 15,000 routers exposed to the internet and many retaining default credentials. Exploitation is confirmed in the wild: a Mirai botnet variant has weaponized the flaw for DDoS attacks, and the RondoDox botnet is also targeting it, consistent with a high EPSS score (84.2% probability of exploitation within 30 days, 100th percentile).

Do: Update F3x24/F3x36 devices to the latest firmware available from Four-Faith and verify apply.cgi handling is fixed; as an immediate mitigation, change default administrator credentials and restrict HTTP management access to trusted networks. Check devices for signs of botnet infection (unexpected outbound traffic or Crontab/persistence changes) and prioritize patching given confirmed in-the-wild exploitation by Mirai and RondoDox botnets.

7.284% PoC ×2
  • Four-Faith F3x24 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
  • Four-Faith F3x36 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
large≈15,000+ internet-exposed routers (headline scan count; total deployments likely higher)
CVE-2024-7029
Commands can be injected over the network and executed without authentication.

Commands can be injected over the network and executed without authentication.

NVD description · AI analysis pending
8.739% PoC
  • avtech avm1203 firmware
CVE-2024-8957
OS Command Injection in PTZOptics PT30X-SDI/NDI Cameras Enables Chained RCE

PTZOptics PT30X-SDI and PT30X-NDI-XX-G2 cameras running firmware before 6.3.40 fail to sufficiently validate the ntp_addr configuration value, enabling an OS command injection flaw (CWE-78) that triggers when the camera's ntp_client is started. On its own the flaw requires high-privileged access, consistent with its CVSS 3.1 base score of 7.2, but when chained with CVE-2024-8956 it can be reached by a remote, unauthenticated attacker. Successful exploitation yields arbitrary OS command execution on the camera with high impact to confidentiality, integrity, and availability. Any organization running affected PT30X-series firmware is exposed, with the greatest risk to cameras that are directly reachable from the internet. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-04, indicating in-the-wild exploitation, and a public GreyNoise write-up documents the 0-day RCE alongside an EPSS exploitation probability of 81%.

Do: Upgrade PT30X-SDI and PT30X-NDI-XX-G2 cameras to firmware 6.3.40 or later per vendor instructions, or apply vendor mitigations or discontinue use per CISA's KEV required action. Audit devices for internet exposure (port forwards, NAT rules, cloud relay access) and restrict management and NTP-related interfaces to trusted networks. Ensure CVE-2024-8956 is also remediated, since chaining it with this bug is what enables unauthenticated remote command execution.

7.281% KEV PoC
  • PTZOptics PT30X-SDI camera firmware all versions before 6.3.40
  • PTZOptics PT30X-NDI-XX-G2 camera firmware all versions before 6.3.40
moderatelikely tens of thousands of PT30X-series cameras deployed worldwide, with only a subset (low thousands or fewer) directly internet-exposed
Full article309 words · extracted from securityaffairs.com · click to collapse

Researchers warn of a campaign exploiting AVTECH IP cameras and Huawei HG532 routers to create a Mirai botnet variant called Murdoc Botnet.

Murdoc Botnet is a new Mirai botnet variant that targets vulnerabilities in AVTECH IP cameras and Huawei HG532 routers, the Qualys Threat Research Unit reported.

The botnet has been active since at least July 2024, the experts discovered that over 1300 IPs were found active on this campaign. Most of the infected systems are in Malaysia, Thailand, Mexico, and Indonesia.

Researchers found over 100 servers distributing Mirai malware and communicating with compromised IPs, indicating the campaign is ongoing.

“Mirai malware, here dubbed as Murdoc Botnet, is a prominent malware family for *nix systems. It mainly targets vulnerable AVTECH and Huawei devices. This botnet also uses some existing exploits (CVE-2024-7029CVE-2017-17215) to download the next-stage payloads.” reads the advisory.

The payload targets AVTECH cameras, using command-line injection to fetch, execute, and remove shell scripts. The Qualys Threat Research Unit discovered over 500 samples containing ELF files and ShellScript files. The ShellScript is loaded onto IoT devices such as IP cameras, and network devices, revealing that the Murdoc Botnet specifically targets IoT devices via this mechanism, leveraging C2 servers for new Mirai variant propagation.

The bot shell script uses GTFOBins to fetch, grant execution permissions, execute, and then remove the payload.

Recently, QiAnXin XLab experts observed the Mirai-based Gayfemboy botnet delivering its bot by exploiting more than 20 vulnerabilities, they also attempted to exploit Telnet weak credentials. The researchers discovered that attackers targeted the zero-day vulnerability CVE-2024-12856 in Four-Faith industrial routers along with several unknown vulnerabilities affecting Neterbit and Vimar devices.

Gayfemboy exploits various vulnerabilities, including CVE-2013-3307CVE-2021-35394CVE-2024-8957, and others in DVRs, routers, and security appliances.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, botnet)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/173294/cyber-crime/new-mirai-botnet-variant-murdoc-botnet-targets-avtech-ip-cameras-and-huawei-hg532-routers.html