The publication of POC (Proof Of Concept) exploit code in vulnerabilities databases resulted in the increased spread of the well-known Mirai Botnet Malware. The code was made public on October 31st but its spread was detected on November 22nd, according to Qihoo 360 Netlab researcher Li Fengpei.
The POC is for a vulnerability in the Zyxel PK5001Z router model. The (CVE-2016-10401) concerns a hidden superuser password (zyad5001 ) which gives an unauthorized user root level. It is noteworthy that several of these models were released on the market with Telnet Credential: Admin/CentryL1nk and Admin/QwestModem. Therefore, using these credentials and the su password, someone would gain root access.
The Mirai Botnet Malware works by scanning the internet for devices with exposed Telnet ports, then using default credentials to log in to them and install the Mirai DdoS Malware. Last Wednesday, for about 60 hours, there was increased activity from Mirai on ports 23 and 2323.
Researchers at Netlab say the entire operation likely originated in Argentina, as most infected devices used ISP Telefonica De Argentina to connect to the Internet. Around 100,000 IPs were scanned by Mirai in total, of which 65,700 were located in Argentina.
The good news is that Mirai doesn't leave any functionality in the router that would cause it to recreate itself, so if someone reboots the router, the malware is gone. On the other hand, the Mirai Botnet seems to be trying to survive by scanning more and more devices every day.


