
A new version of Mirai Malware , created by hackers , exploits a remote code execution vulnerability ( CVE-2020-9054 ), which was recently patched in Zyxel network-attached storage (NAS) devices
The vulnerability has been classified as “critical» and has been scored at 9.8 CVE. This specific flaw allows the Mukashi botnet to carry out brute force attacks on logins using different combinations of default credentials.
Zyxel NAS devices running firmware versions up to 5.21 are vulnerable to exploiting this new variant of Malware.
The vulnerability was initially discovered as a zero day and the exploit code was made available for sale by a group of hackers who attempted to exploit the Emotet malware.
The researchers disclosed the vulnerability on March 12, 2020, when the intruder attempted to download a shell script to the tmp directory, execute the retrieved script and remove its data from the vulnerable device.
Mukashi is also able to launch a DDOS on the infected machine, receiving the command from the C2 server.
How does it work?
Initially, the hackers probe TCP port 23 of random hosts belonging to the targeted network. For this purpose, they use the Mukashi bot and perform a brute force attack on logins, using default credentials. They then report a successful connection attempt to the C2 server.
Upon successful execution, the malware displays the message “Protecting your device from further infections” in the console and binds to TCP port 23448 to ensure that this action is performed before proceeding with the intended operation.
The researchers recommend that users download the latest firmwareand set a complex password to prevent brute force attacks.
