HomeSecurityMozi botnet: Responsible for most attacks on IoT devices

Mozi botnet: Responsible for most attacks on IoT devices

According to IBM, Mozi, a relatively new botnet , is responsible for the increase in Internet of Things (IoT) botnet activity.

Mozi botnet

The Mozi botnet was heavily used over the past year, accounting for 90% of IoT network trafficobserved between October 2019 and June 2020. However, researchers found that it carried out attacks without attempting to remove its competitors from compromised systems.

On the other hand, the sharp increase in attacks on IoT devices is not solely due to botnet effectiveness. It is largely due to the increased use of IoT devices around the world. More devices mean more opportunities for attacks. According to IBM, there are approximately 31 billion IoT devices worldwide.

Researchers believe that the success of the Mozi botnet is based on the use of “command injection (CMDi)” attacks, which rely on misconfigurations in IoT devices. The combination of increased use of IoT devices and incorrect protocols is responsible for the increase in attacks. Of course, prolonged remote working due to COVID-19also plays a significant role.

Researchers have observed that almost all attacks targeting IoT devices use the CMDi technique for initial access. The Mozi botnet exploits CMDi using a “wget” shell command and then violates permissions to facilitate attackers’ interaction with the target system.

IBM said that on vulnerable devices, a file named “mozi.a” and then executed on the MIPS architecture. The attack targets machines using RISC (reduced instruction set computer architecture—MIPS is a “RISC instruction set architecture”) and could allow a hacker to modify the firmware to install additional malware.

The Mozi botnet targets several vulnerabilities to infect IoT devices: CVE-2017-17215 (Huawei HG532), CVE-2018-10561 / CVE-2018-10562 (GPON Routers), CVE-2014-8361 (Realtek SDK), CVE-2008-4873 (Sepal SPBOARD), CVE-2016-6277 (Netgear R7000 / R6400), CVE-2015-2051 (D-Link Devices), Eir D1000 wireless router command injection, Netgear setup.cgi RCE, MVPower DVR command execution, D-Link UPnP SOAP command execution and RCE affecting multiple CCTV-DVR vendors.

IoT

The hackers behind the Mozi botnet use infrastructure located mainly in China (84%).

“The Mozi botnet is a peer-to-peer (P2P) botnet based on the distributed sloppy hash table (DSHT) protocol, which can spread through IoT device exploits and weak telnet passwords,” IBM says.

According to IBM, the botnet can be used to carry out denial-of-service attacks (DDoS), execute malicious commands, execute additional payloads , and gather information.

According to SecurityWeek, researchers emphasize that organizations using IoT devices should pay attention to this increasingly common threat. “Command injection” remains the main form of infection, so it is important to change the default device settings and perform continuous checks for potential security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS