ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New Mirai Variant and ZHtrap Botnet Malware Emerge in the Wild

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-8361
Improper Input Validation in Realtek SDK miniigd SOAP Service Enables Remote RCE

The Realtek SDK, a software development kit embedded in routers, gateways, and similar network equipment sold under many OEM brands, contains an improper input validation flaw (CWE-20) in its miniigd UPnP SOAP service. A remote, unauthenticated attacker can trigger it by sending a crafted NewInternalClient request to the vulnerable SOAP interface, causing execution of malicious code on the device. Successful exploitation gives attackers control of affected devices, which can be used for botnet recruitment, staging further attacks, or ransomware operations. Affected parties are owners of devices built on the Realtek SDK, particularly routers and gateways with the UPnP service exposed to the internet. Exploitation is ongoing: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-09-18 and EPSS assigns it a 100% probability of exploitation within 30 days, though ransomware use is not confirmed.

Do: Inventory devices that use the Realtek SDK and check whether the miniigd UPnP/SOAP service is reachable from untrusted networks; apply firmware updates from your device vendor as soon as available, or per CISA's required action, disable UPnP or block the service from internet exposure if mitigations are unavailable. No patch level is published in this dataset, so verify fix status against OEM advisories and review device logs for crafted NewInternalClient SOAP requests.

100% KEV
  • Realtek SDK
mass≈1,000,000+ devices (hundreds of thousands of internet-exposed hosts observed in public scans; SDK embedded in many OEM routers)
CVE-2019-19356
Command Injection RCE as Root in Netis WF2419 Routers

Netis WF2419 routers contain an operating-system command injection flaw (CWE-78) in the router's web management page that allows an attacker to execute arbitrary commands with root privileges. The flaw is triggered through the web management interface, where crafted input is passed to a system command without adequate sanitization, enabling unauthenticated or low-privilege access to escalate to full command execution as root. An attacker who exploits it gains complete control of the router — root-level code execution — which can be used to intercept or manipulate traffic, pivot into the local network, or enlist the device in a botnet. Any user or organization running a Netis WF2419 router is affected, with the greatest risk on devices whose web management page is reachable from the WAN/internet. Although no public proof-of-concept is known and no CVSS score is published, CISA added the issue to the Known Exploited Vulnerabilities catalog on 2021-11-03 (confirming in-the-wild exploitation; ransomware use not reported), and the 98th-percentile EPSS of 28.2% indicates an elevated probability of exploitation over the next 30 days.

Do: Upgrade WF2419 firmware to the latest release from Netis per the vendor's instructions, as required by CISA (no specific fixed firmware version is provided in this data — check with Netis). Disable or restrict WAN-side remote administration so the web management page is not reachable from the internet, and review device logs for signs of exploitation or compromise. Given the KEV listing and 98th-percentile EPSS despite the missing CVSS score, treat this as a high-priority patch for any WF2419 units in service.

7.528% KEV PoC ×3
  • Netis WF2419 router (WF2419 Devices)
mass≈1–2 million+ deployed devices worldwide, with likely on the order of 100,000+ internet-exposed (estimate)
CVE-2020-25506
Command Injection in D-Link DNS-320 system_mgr.cgi Allows Remote Code Execution

CVE-2020-25506 is an operating system command injection flaw (CWE-78) in the system_mgr.cgi component of D-Link DNS-320 network-attached storage devices. An attacker can trigger it by sending crafted input to the system_mgr.cgi handler of the device's web management interface, causing attacker-controlled data to be executed as operating system commands. Successful exploitation may allow remote code execution on the NAS, giving an attacker control over the device and its stored data. Any D-Link DNS-320 running affected firmware is at risk; the available data does not specify affected or fixed version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and current EPSS assigns roughly a 100% probability of exploitation within 30 days, though a specific ransomware association has not been confirmed.

Do: Apply D-Link firmware updates for the DNS-320 per the vendor's instructions, as required by CISA's KEV listing. Until patched, stop exposing the device's web interface to the internet (remove port forwarding/DMZ rules or restrict access to trusted management networks). Because exploitation is being observed, check NAS logs for unexpected requests to system_mgr.cgi and signs of unauthorized command execution.

9.8100% KEV PoC
  • D-Link DNS-320 (network-attached storage device)
largetens of thousands of internet-exposed DNS-320 devices (estimate; total installed base likely higher)
CVE-2020-26919
Missing Function-Level Access Control in NETGEAR JGS516PE Smart Managed Switches

CVE-2020-26919 is a missing function-level access control flaw in NETGEAR JGS516PE ProSAFE 16-port Gigabit PoE+ Smart Managed Plus switches running firmware before 2.6.0.43. An unauthenticated remote attacker can invoke privileged switch functions over the network without authorization, consistent with the CVSS 9.8 critical score (network vector, no privileges or user interaction required). Successful exploitation grants the attacker full functional control of the switch's management functions, with high impact on confidentiality, integrity, and availability of the device. Any organization or site running a JGS516PE switch on affected firmware is exposed, particularly where the management interface is reachable from untrusted networks. The flaw is listed in the CISA Known Exploited Vulnerability Catalog (added 2021-11-03), indicating it is known to be exploited in the wild, and related reporting on Mirai variants targeting network devices suggests active scanning and botnet interest in this class of equipment.

Do: Upgrade JGS516PE switch firmware to version 2.6.0.43 or later per NETGEAR's instructions, as required by the CISA KEV listing. Restrict the switch's management interface (web and network management protocols) to trusted management VLANs or administrative networks and avoid internet exposure. Check whether the device appears in KEV-driven scanning activity and monitor for Mirai-style botnet targeting of network infrastructure.

9.857% KEV
  • NETGEAR JGS516PE firmware (ProSAFE 16-port Gigabit PoE+ Smart Managed Plus switch) All firmware versions before 2.6.0.43
largeon the order of tens of thousands of deployed JGS516PE switches, with a likely lower but non-trivial subset (thousands to tens of thousands) having management…
CVE-2021-22502
Unauthenticated Command Injection RCE in Micro Focus Operation Bridge Reporter

CVE-2021-22502 is an unauthenticated OS command injection flaw (CWE-78) in Micro Focus Operation Bridge Reporter (OBR) version 10.40, rated critical (CVSS 9.8) because it is reachable over the network with no privileges or user interaction required. By sending crafted input to the exposed OBR service, an attacker can inject operating-system commands that are executed directly on the OBR server. Successful exploitation yields full remote code execution with the privileges of the affected service, giving attackers a foothold in enterprise IT operations environments. Organizations running OBR 10.40 — an enterprise IT-operations analytics/reporting server — are affected, particularly where the OBR interface is reachable from untrusted networks. Exploitation status is high-concern: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, a public proof-of-concept for unauthenticated command injection exists, and EPSS puts the 30-day exploitation probability at 96.7% (top percentile).

Do: Apply the vendor update for Operation Bridge Reporter per Micro Focus/OpenText instructions, as required by the CISA KEV catalog; confirm the deployed OBR build resolves 10.40. Until patched, restrict network access to the OBR server (firewall rules, VPN-only access) and hunt for signs of compromise such as unexpected processes, suspicious outbound connections, or web-shell artifacts on the server.

9.897% KEV PoC
  • Micro Focus Operation Bridge Reporter (OBR) 10.40
moderatelikely on the order of thousands of enterprise deployments worldwide (roughly 1,000–10,000 systems), with only a fraction internet-exposed; exact counts unknown
CVE-2021-27561
Unauthenticated Root Command Injection in Yealink Device Management

CVE-2021-27561 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in Yealink Device Management (DM) 3.6.0.20, which CISA also characterizes as a server-side request forgery issue. A remote attacker can send a crafted, unauthenticated HTTP request to the /sm/api/v1/firewall/zone/services URI to inject operating system commands that execute with root privileges on the DM server. Successful exploitation yields full root control of the management server, allowing an attacker to pivot into the managed VoIP/UC environment, move laterally inside the network, or enroll the host in an IoT-style botnet. The flaw affects organizations running Yealink Device Management to administer fleets of Yealink IP phones, and it is trivially exploitable over the network with no user interaction. It was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, and the recent emergence of Mirai-variant botnets targeting network devices is consistent with active mass-scanning for this class of unauthenticated injection flaw; EPSS puts the 30-day exploitation probability at roughly 83%.

Do: Upgrade Yealink Device Management to a fixed release per Yealink's instructions (the confirmed affected version is 3.6.0.20); CISA's required action is to apply vendor updates. Until patched, restrict access to the DM web interface to trusted management networks and verify it is not internet-exposed. Check access logs for unauthenticated requests to /sm/api/v1/firewall/zone/services, which would indicate probing or exploitation.

9.883% KEV
  • Yealink Device Management 3.6.0.20 confirmed affected (command injection as root); other/prior versions not specified in the source data
moderatethousands (order of magnitude 1k–10k) of deployed DM servers, many internet-exposed
CVE-2021-27562
Out-of-Bounds Write in Arm Trusted Firmware-M Through 1.2

Arm Trusted Firmware-M (TF-M), the open-source reference secure firmware for Cortex-M microcontrollers with TrustZone, through version 1.2 contains an out-of-bounds write (CWE-787) in the non-secure processing environment (NSPE) handler-mode path. The flaw is triggered when software running in the non-secure world calls a secure function while in handler mode, which can corrupt memory or secure state. A successful trigger can halt the system, overwrite secure data, or print secure data to output; the scored impact is high availability (CVSS 3.1: 5.5, AV:L/PR:L), so exploitation requires local code execution in the non-secure world. Any device whose firmware is built on TF-M 1.2 or earlier is affected, spanning the many silicon vendors and IoT products that ship Arm's reference secure firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, though no public PoC is documented and ransomware use is unknown.

Do: Apply updates per vendor instructions: device makers and OEMs should rebuild firmware on a TF-M release newer than 1.2, and device owners should install updated firmware/SDKs from their silicon vendor or OEM. Check which of your microcontroller-based products (e.g., IoT endpoints) use Trusted Firmware-M and whether they run third-party or non-secure applications that could invoke secure functions; because exploitation requires local code execution, prioritize devices accepting remote code or app deployment. Containment is not otherwise available, as the fix is in the secure firmware itself.

5.53% KEV
  • trustedfirmware (Arm Trusted Firmware-M project) Trusted Firmware-M through 1.2 (all versions up to and including 1.2)
masspotentially millions of embedded/IoT devices built on TF-M 1.2 or earlier (no public install counts; broad but unquantified)

Indicators of compromiseAll →

TypeIndicatorContext
ipv47.5.1.4nerability that was patched on legacy products in 2015 with 7.5.1.4-43sv and 8.0.0.4-25sv releases," SonicWall said in a statem
ipv48.0.0.4as patched on legacy products in 2015 with 7.5.1.4-43sv and 8.0.0.4-25sv releases," SonicWall said in a statement to The Hacker
Full article780 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 16, 2021

Cybersecurity researchers on Monday disclosed a new wave of ongoing attacks exploiting multiple vulnerabilities to deploy new Mirai variants on internet connected devices.

"Upon successful exploitation, the attackers try to download a malicious shell script, which contains further infection behaviors such as downloading and executing Mirai variants and brute-forcers," Palo Alto Networks' Unit 42 Threat Intelligence Team said in a write-up.

The rash of vulnerabilities being exploited include:

  • VisualDoor - a SonicWall SSL-VPN remote command injection vulnerability that came to light earlier this January
  • CVE-2020-25506 - a D-Link DNS-320 firewall remote code execution (RCE) vulnerability
  • CVE-2021-27561 and CVE-2021-27562 - Two vulnerabilities in Yealink Device Management that allow an unauthenticated attacker to run arbitrary commands on the server with root privileges
  • CVE-2021-22502 - an RCE flaw in Micro Focus Operation Bridge Reporter (OBR), affecting version 10.40
  • CVE-2019-19356 - a Netis WF2419 wireless router RCE exploit, and
  • CVE-2020-26919 - a Netgear ProSAFE Plus RCE vulnerability

"The VisualDoor exploit in question targets an old SSL-VPN firmware vulnerability that was patched on legacy products in 2015 with 7.5.1.4-43sv and 8.0.0.4-25sv releases," SonicWall said in a statement to The Hacker News. "It is not viable against any properly patched SonicWall appliances."

Also included in the mix are three previously undisclosed command injection vulnerabilities that were deployed against unknown targets, one of which, according to the researchers, has been observed in conjunction with a separate botnet by the name of MooBot.

The attacks are said to have been detected over a month-long period starting from February 16 to as recent as March 13.

Regardless of the flaws used to achieve successful exploitation, the attack chain involves the use of wget utility to download a shell script from the malware infrastructure that's then used to fetch Mirai binaries, a notorious malware that turns networked IoT devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

Besides downloading Mirai, additional shell scripts have been spotted retrieving executables to facilitate brute-force attacks to break into vulnerable devices with weak passwords.

"The IoT realm remains an easily accessible target for attackers. Many vulnerabilities are very easy to exploit and could, in some cases, have catastrophic consequences," the researcher said.

New ZHtrap Botnet Traps Victims Using a Honeypot

In a related development, researchers from Chinese security firm Netlab 360 discovered a new Mirai-based botnet called ZHtrap that makes use of a honeypot to harvest additional victims, while borrowing some features from a DDoS botnet known as Matryosh.

While honeypots typically mimic a target for cyber criminals so as to take advantage of their intrusion attempts to glean more information about their modus operandi, the ZHtrap botnet uses a similar technique by integrating a scanning IP collection module for gathering IP addresses that are used as targets for further worm-like propagation.

It achieves this by listening on 23 designated ports and identifying IP addresses that connect to these ports, then using the amassed IP addresses to inspect them for four vulnerabilities to inject the payload -

"ZHtrap's propagation uses four N-day vulnerabilities, the main function is DDoS and scanning, while integrating some backdoor features," the researchers said. "Zhtrap sets up a honeypot on the infected device, [and] takes snapshots for the victim devices, and disables the running of new commands based on the snapshot, thus achieving exclusivity over the device."

Once it has taken over the devices, ZHtrap takes a cue from the Matryosh botnet by using Tor for communications with a command-and-control server to download and execute additional payloads.

Noting that the attacks began from February 28, 2021, the researchers said ZHtrap's ability to turn infected devices into honeypots marks an "interesting" evolution of botnets to facilitate finding more targets.

These Mirai-based botnets are the latest to spring up on the threat landscape, in part fanned by the availability of Mirai's source code on the Internet since 2016, opening the field wide open for other attackers to build their own variants.

Last March, researchers discovered a Mirai variant called "Mukashi," which was found targeting Zyxel network-attached storage (NAS) devices to conscript them into a botnet. Then in October 2020, Avira's IoT research team identified another variant of the Mirai botnet named "Katana," which exploited remote code execution vulnerabilities to infect D-Link DSL-7740C routers, DOCSIS 3.1 wireless gateway devices, and Dell PowerConnect 6224 Switches.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/03/new-mirai-variant-and-zhtrap-botnet.html