ZeroHour
Security Affairspublished ()ingested @securityaffairs

Anarchy botmaster builds a botnet of 18,000 Huawei routers in a few hours

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-8361
Improper Input Validation in Realtek SDK miniigd SOAP Service Enables Remote RCE

The Realtek SDK, a software development kit embedded in routers, gateways, and similar network equipment sold under many OEM brands, contains an improper input validation flaw (CWE-20) in its miniigd UPnP SOAP service. A remote, unauthenticated attacker can trigger it by sending a crafted NewInternalClient request to the vulnerable SOAP interface, causing execution of malicious code on the device. Successful exploitation gives attackers control of affected devices, which can be used for botnet recruitment, staging further attacks, or ransomware operations. Affected parties are owners of devices built on the Realtek SDK, particularly routers and gateways with the UPnP service exposed to the internet. Exploitation is ongoing: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-09-18 and EPSS assigns it a 100% probability of exploitation within 30 days, though ransomware use is not confirmed.

Do: Inventory devices that use the Realtek SDK and check whether the miniigd UPnP/SOAP service is reachable from untrusted networks; apply firmware updates from your device vendor as soon as available, or per CISA's required action, disable UPnP or block the service from internet exposure if mitigations are unavailable. No patch level is published in this dataset, so verify fix status against OEM advisories and review device logs for crafted NewInternalClient SOAP requests.

100% KEV
  • Realtek SDK
mass≈1,000,000+ devices (hundreds of thousands of internet-exposed hosts observed in public scans; SDK embedded in many OEM routers)
CVE-2017-17215
Huawei HG532 with some customized versions has a remote code execution vulnerability.

Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.

NVD description · AI analysis pending
8.878%
  • huawei hg532 firmware

Indicators of compromiseAll →

TypeIndicatorContext
ipv4104.244.72.82nubhav (@ankit_anubhav) July 18, 2018 Ketashi botnet hxxp://104.244.72.82 hxxp://104.244.72.82/sister hxxp://104.244.72.82/k http://1
md5c3cf80d13a04996b68d7d20eaf1baea8ing public for obvious reasons. The bin in his botnet md5 > c3cf80d13a04996b68d7d20eaf1baea8 As one can see, it uses only 1 exploit, 2017-17215. 2/n pic
urlhttp://104.244.72.82Ankit Anubhav (@ankit_anubhav) July 18, 2018 Ketashi botnet hxxp://104.244.72.82 hxxp://104.244.72.82/sister hxxp://104.244.72.82/k http://1
urlhttp://104.244.72.82/kshi botnet hxxp://104.244.72.82 hxxp://104.244.72.82/sister hxxp://104.244.72.82/k http://104.244.72.82/gpon #ketashi @360Netlab @ankit_anubha
urlhttp://104.244.72.82/sister_anubhav) July 18, 2018 Ketashi botnet hxxp://104.244.72.82 hxxp://104.244.72.82/sister hxxp://104.244.72.82/k http://104.244.72.82/gpon #ketashi @
Full article670 words · extracted from securityaffairs.com · click to collapse

The popular Anarchy botmaster builds a botnet of 18,000 Huawei routers in a few hours, and it is also planning to target vulnerable Realtek routers.

NewSky Security first reported the born a new huge botnet, in just one day the botmaster compromised more than 18,000 Huawei routers.

NewSky security researcher Ankit Anubhav announced that the botnet had already infected 18,000 routers. The disconcerting aspect of the story is that the hacker gathered a so huge number of devices in a limited period of time, without using any zero-day issue.

The same botnet was today reported by experts from other security firms, including  Qihoo 360 Netlab, Greynoise, and Rapid7.

We were tracking this botnet yesterday, the claimed 18000+ huawai router number is probably inflated, as we were able to take a peek at the file which highly likely stored the infected ips, the total count was 10901. and attached is the graphic of the C2 for this botnet, big one. https://t.co/gQBStREpCI

— 360 Netlab (@360Netlab) July 19, 2018

The botmaster is a hacker that goes online with the moniker “Anarchy,” according to Anubhav he was previously identified as Wicked and was involved in the born of the homonymous Mirai variant.

The Wicked Mirai botnet was first spotted by researchers at Fortinet, and Anubhav published on the NewSky’s blog and interview with the hacker.

Wicked/Anarchy is believed to be the threat actor behind other Mirai variants, including, Omni, and Owari (Sora).

As explained at the beginning of this post, Anarchy did not use any specific exploit to gather tens of thousands of devices in a few hours. The CVE-2017-17215 is a well-known vulnerability that was used by many other botnets, including the Mirai Satori, to gather zombies.

The CVE-2017-17215 zero-day vulnerability in the Huawei home router residing in the fact that the TR-064 technical report standard, which was designed for local network configuration, was exposed to WAN through port 37215 (UPnP – Universal Plug and Play).

The exploit code used to target the Huawei routers is publicly available, in December Ankit Anubhav discovered it on Pastebin.com..

“NewSky Security observed that a known threat actor released working code for Huawei vulnerability CVE-2017–17215 free of charge on Pastebin this Christmas. This exploit has already been weaponized in two distinct IoT botnet attacks, namely Satori and Brickerbot.” stated a blog post published by Anubhav.

At the time, the exploit code for the CVE- 2017-17215 was used by a hacker identified as “Nexus Zeta” to spread the Satori bot (aka Okiku).

The availability of the code online represents a serious risk, it could become a commodity in the criminal underground, vxers could use it to build their botnet.

Satori isn’t the only botnet leveraging the CVE-2017-17215 exploit code, earlier in December, the author of the Brickerbot botnet that goes online with the moniker “Janitor” released a dump which contained snippets of Brickerbot source code.

NewSky Security analyzed the code and discovered the usage of the exploit code CVE-2017–17215, this means that the code was available in the underground for a long.

According to Bleeping Computer, Anarchy told Anubhav that he also plans to target the CVE-2014-8361 flaw in Realtek routers that is exploitable via port 52869.

“Testing has already started for the Realtek exploit during the night,” Anubhav told Bleeping Computer in a private conversation today. [Update: Both Rapid7 and Greynoise are confirming that scans for Realtek have gone through the roof today.]

Below the md5 and the C&C associated with the threat:

The attacker Anarchy has shared a list of infected victim IPs which at that point, I am not making public for obvious reasons. The bin in his botnet md5 >
c3cf80d13a04996b68d7d20eaf1baea8

As one can see, it uses only 1 exploit, 2017-17215. 2/n pic.twitter.com/F5BNNbf3bM

— Ankit Anubhav (@ankit_anubhav) July 18, 2018

Ketashi botnet
hxxp://104.244.72.82
hxxp://104.244.72.82/sister
hxxp://104.244.72.82/k
http://104.244.72.82/gpon#ketashi @360Netlab @ankit_anubhav @campuscodi

— SMII Mondher (@smii_mondher) July 19, 2018

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Anarchy botnet, IoT)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/74599/uncategorized/anarchy-botnet-huawei.html