ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

New DDoS Campaign Exploits IoT Devices and Server Misconfigurations

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-18368
Unauthenticated OS Command Injection in Zyxel/Billion TrueOnline Routers

CVE-2017-18368 is a critical (CVSS 9.8) unauthenticated OS command injection (CWE-78) in the Remote System Log forwarding function of Zyxel P660HN-T1A (v1 and v2) and Billion 5200W-T routers distributed by Thailand ISP TrueOnline. An unauthenticated attacker who can reach the router's web management interface sends a crafted remote_host parameter to the ViewLog.asp page, with no credentials or user interaction required. Successful injection executes arbitrary operating-system commands on the device, giving the attacker full control of the router (e.g., botnet recruitment, traffic/DNS manipulation, or pivoting into the subscriber's LAN). Only TrueOnline-issued units of these models are affected, meaning Thai broadband subscribers deployed with this CPE. The flaw is in CISA's KEV catalog (added 2023-08-07), carries a 94.4% EPSS (100th percentile), and related reporting shows IoT botnets (e.g., Gafgyt campaigns against End-of-Life Zyxel routers and multi-exploit campaigns like RondoDox) actively targeting such devices.

Do: Update affected routers to the latest firmware available from Zyxel/Billion or via TrueOnline's ISP update process, noting these models are End-of-Life so hardware replacement is the durable fix. Until patched, restrict or disable WAN-side access to the router's web management interface (the flaw is reachable unauthenticated via ViewLog.asp) and audit devices for signs of botnet compromise. Per the CISA KEV required action, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

9.894% KEV PoC ×3
  • Zyxel P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 (TrueOnline-distributed firmware; model listed broadly as affected by CISA)
  • Zyxel P660HN-T1A v2
  • Billion 5200W-T
mass≈1 million (order-of-magnitude estimate) TrueOnline-issued devices, of which thousands to tens of thousands expose the management interface to the internet at…
CVE-2021-20090
Unauthenticated Path Traversal in Arcadyan Buffalo Router Firmware

CVE-2021-20090 is a path traversal flaw (CWE-22) in the web interface of Arcadyan's Buffalo router firmware. By sending crafted HTTP requests containing directory traversal sequences, an unauthenticated, remote attacker can bypass the device's authentication. Successful exploitation grants access to sensitive information and otherwise protected functionality on the router without valid credentials. The flaw affects multiple router models across several different vendors, because Arcadyan's Buffalo firmware is embedded in a range of OEM and ISP-distributed products. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2021-11-03, and EPSS rates the probability of exploitation within 30 days at 100% (100th percentile).

Do: Apply firmware updates from the router vendor as directed in the CISA KEV required action. Until patched, restrict or disable WAN-side remote management of the device's web interface. Review router configurations for unauthorized changes after patching, since unauthenticated remote access was possible.

9.8100% KEV PoC ×2
  • Arcadyan Buffalo Firmware
massplausibly millions of deployed consumer/ISP routers; internet-exposed subset unknown
Full article394 words · extracted from infosecurity-magazine.com · click to collapse

A widespread distributed denial-of-service (DDoS) campaign leveraging accessible tools and targeting IoT devices and enterprise servers has been uncovered by security researchers.

Orchestrated by a threat actor known as Matrix, the operation highlights how minimal technical knowledge combined with public scripts can enable global scale cyber-attacks.

Matrix’s attack framework, analyzed in detail by Aqua Nautilus, focuses on exploiting vulnerabilities and misconfigurations across internet-connected devices.

The campaign employs brute-force attacks, weak credentials and known exploits to build a botnet capable of significant disruption. This reflects a growing trend where ‘script kiddies’ leverage publicly available tools to execute sophisticated attacks.

Key Characteristics of the Attack

Matrix’s operation is a comprehensive “do-it-yourself” approach, scanning, exploiting and deploying malware on:

  • Routers: Exploits include vulnerabilities such as CVE-2017-18368 and CVE-2021-20090

  • DVRs and IP cameras: Using flaws in devices with the Hi3520 platform for unauthorized access

  • Enterprise protocols: Targeting Apache Hadoop’s YARN, HugeGraph servers and SSH misconfigurations

  • IoT devices: Exploits on lightweight Linux distributions like uClinux in telecom equipment

The attacks heavily rely on default or weak passwords, with 80% of identified credentials tied to root or admin users. These tactics emphasize how failure to adopt basic security measures – such as changing factory-default credentials – exposes devices to compromise.

Target Scope and Implications

Matrix’s targets span cloud service providers (CSPs), smaller enterprises and IoT-heavy regions like China and Japan. Analysis revealed up to 35 million potential devices could be affected, suggesting a botnet of 350,000 to 1.7 million devices, depending on vulnerability rates.

The campaign underscores a shift toward exploiting corporate vulnerabilities alongside IoT systems. Historically, cryptomining dominated such attacks, but Matrix’s focus includes both production and development servers, amplifying the risk for enterprise environments.

Read more on mitigating DDoS threats: UK Council Sites Recover Following Russian DDoS Blitz

Tools and Infrastructure

Matrix utilizes a mix of Python, Shell and Golang-based scripts sourced from GitHub and other platforms. Tools like Mirai variants, SSH scanners and Discord bots highlight the integration of pre-existing frameworks into customized campaigns. The threat actor also monetizes services via Telegram, offering DDoS plans for cryptocurrency payments.

While Matrix appears to lack advanced capabilities, the ease of assembling and operating these tools exemplifies the growing risk posed by low-sophistication actors armed with accessible resources.

Addressing these threats requires robust security measures, including regular updates, strong credentials and monitoring for exposed vulnerabilities.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ddos-campaign-exploits-iot-devices/