According to IBM, Mozi, a relatively new botnet , is responsible for the increase in Internet of Things (IoT) botnet activity.

The Mozi botnet was heavily used over the past year, accounting for 90% of IoT network trafficobserved between October 2019 and June 2020. However, researchers found that it carried out attacks without attempting to remove its competitors from compromised systems.
On the other hand, the sharp increase in attacks on IoT devices is not solely due to botnet effectiveness. It is largely due to the increased use of IoT devices around the world. More devices mean more opportunities for attacks. According to IBM, there are approximately 31 billion IoT devices worldwide.
Researchers believe that the success of the Mozi botnet is based on the use of “command injection (CMDi)” attacks, which rely on misconfigurations in IoT devices. The combination of increased use of IoT devices and incorrect protocols is responsible for the increase in attacks. Of course, prolonged remote working due to COVID-19also plays a significant role.
Researchers have observed that almost all attacks targeting IoT devices use the CMDi technique for initial access. The Mozi botnet exploits CMDi using a “wget” shell command and then violates permissions to facilitate attackers’ interaction with the target system.
IBM said that on vulnerable devices, a file named “mozi.a” and then executed on the MIPS architecture. The attack targets machines using RISC (reduced instruction set computer architecture—MIPS is a “RISC instruction set architecture”) and could allow a hacker to modify the firmware to install additional malware.
The Mozi botnet targets several vulnerabilities to infect IoT devices: CVE-2017-17215 (Huawei HG532), CVE-2018-10561 / CVE-2018-10562 (GPON Routers), CVE-2014-8361 (Realtek SDK), CVE-2008-4873 (Sepal SPBOARD), CVE-2016-6277 (Netgear R7000 / R6400), CVE-2015-2051 (D-Link Devices), Eir D1000 wireless router command injection, Netgear setup.cgi RCE, MVPower DVR command execution, D-Link UPnP SOAP command execution and RCE affecting multiple CCTV-DVR vendors.

The hackers behind the Mozi botnet use infrastructure located mainly in China (84%).
“The Mozi botnet is a peer-to-peer (P2P) botnet based on the distributed sloppy hash table (DSHT) protocol, which can spread through IoT device exploits and weak telnet passwords,” IBM says.
According to IBM, the botnet can be used to carry out denial-of-service attacks (DDoS), execute malicious commands, execute additional payloads , and gather information.
According to SecurityWeek, researchers emphasize that organizations using IoT devices should pay attention to this increasingly common threat. “Command injection” remains the main form of infection, so it is important to change the default device settings and perform continuous checks for potential security.
