HomeinetMirai Botnet Malware Strikes Again - Targets Zyxel Routers

Mirai Botnet Malware Strikes Again - Targets Zyxel Routers

The publication of POC (Proof Of Concept) exploit code in vulnerabilities databases resulted in the increased spread of the well-known Mirai Botnet Malware. The code was made public on October 31st but its spread was detected on November 22nd, according to Qihoo 360 Netlab researcher Li Fengpei.

Mirai Botnet Malware

The POC is for a vulnerability in the Zyxel PK5001Z router model. The (CVE-2016-10401) concerns a hidden superuser password (zyad5001 ) which gives an unauthorized user root level. It is noteworthy that several of these models were released on the market with Telnet Credential: Admin/CentryL1nk and Admin/QwestModem. Therefore, using these credentials and the su password, someone would gain root access.

The Mirai Botnet Malware works by scanning the internet for devices with exposed Telnet ports, then using default credentials to log in to them and install the Mirai DdoS Malware. Last Wednesday, for about 60 hours, there was increased activity from Mirai on ports 23 and 2323.

Mirai Botnet Malware

 

Researchers at Netlab say the entire operation likely originated in Argentina, as most infected devices used ISP Telefonica De Argentina to connect to the Internet. Around 100,000 IPs were scanned by Mirai in total, of which 65,700 were located in Argentina.

The good news is that Mirai doesn't leave any functionality in the router that would cause it to recreate itself, so if someone reboots the router, the malware is gone. On the other hand, the Mirai Botnet seems to be trying to survive by scanning more and more devices every day.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS