If there's one thing that seems to never end in terms of security, it's malware writers putting their own spin on the old Mirai malware and creating new botnets aimed at haunting IoT and enterprise devices.

It's not even been a month since a large botnet appeared out of nowhere and launched massive attacks against smart devices – either using default credentials to take control of the device or using exploits for old security flaws that device owners didn't patch.
New variant of Mirai called Echobot
The latest variant in this long line of Mirai malware is called Echobot. Since appearing in mid-May, the malware was first described by Palo Alto Networks in a report published in early June and then in a security researcher report by Akamai last week.
The malware itself doesn't bring anything new to the actual Mirai source code, which is not surprising as the Mirai code has remained unchanged over the years.
The Echobot malware follows the trend, but a malware author added modules on top of the original Mirai source code.
When Palo Alto Networks researchers first discovered Echobot in early June, it used exploits for 18 vulnerabilities. In Akamai's report a week later, Echobot was at 26.
Targeting IoT devices and business applications
"What I found most interesting and not so surprising is the inclusion of cross-application vulnerabilities," said Larry Cashdollar, Akamai threat researcher.
For example, instead of sticking to devices with embedded operating systems, such as routers, cameras, and DVRs, IoT botnets now use vulnerabilities in corporate web (Oracle WebLogic) and networking software (VMware SD-WAN) to infect targets and spread malware,” he continued.
This strange way of evolving a botnet using unrelated exploits is not unique to Echobot, but a process that all IoT botnets go through.
From the outside, malware writers appear to choose their exploits randomly, but there is a process to their madness.
As some IoT botnet authors have mentioned in the past, they start by randomly selecting exploits, but only keep those that bring a large number of infected devices (bots) and discard those that don't work.
Exploits are recycled through a botnet within a few days if they don't work. So Echobot's current arsenal of exploits can be thought of as a list of vulnerabilities offered by most bots, as well as a list that device owners and security vendors might want to take a look at, as it provides insight into which devices have been attacked the most.

