For about a year, hackers have been exploiting zero-day vulnerabilities to install malware on Tenda routers and create an IoT (Internet of Things) botnet called “Ttint.” This botnet was first analyzed in a report published late last week by Netlab, the network security division of Chinese tech giant Qihoo 360.Unlike other IoT botnets that have been detected in the past, Netlab researchers said the Ttint IoT botnet is different on several levels.
Specifically, the Ttint IoT botnet not only infects devices to perform DDoS attacks, but also implements 12 different remote access on infected routers, uses routers as proxy servers to relay traffic, alters router firewall and DNS settings, and allows attackers to execute remote commands on infected devices.
According to the company's report, the Ttint IoT botnet appears to have been deployed last year, in November 2019, when Netlab said it detected that the botnet exploited the first zero-day vulnerability in Tenda routers to take over vulnerable devices.

The Ttint IoT botnet continued to exploit this zero-day vulnerability identified as CVE-2020-10987 until July 2020, when Sanjana Sarda, Junior Security Analyst at Independent Security Evaluators, published a detailed report on this vulnerability as well as four other vulnerabilities.
Tenda did not release a firmware patch to mitigate Sarda's findings, but Ttint operators did not wait to find out if the vendor was going to fix bug later. A few weeks later, Netlab discovered that Ttint was exploiting a second zero-day vulnerability in the same Tenda routers.
According to ZDNet, Netlab did not release details about the zero-day vulnerability, fearing that other botnets would start reporting it as well. However, it was not patched, even though Netlab researchers said they informed Tenda.

Netlab noted that any Tenda router running firmware version between AC9 and AC18 should be considered vulnerable. Given that Ttint has changed the DNS settings to infected routers, it is likely to redirect users to malicious sites, therefore the use of any of these routers is not recommended.
Owners of Tenda routers who want to find out if they are using a vulnerable router can find firmware version information in the routers' management console.
IoT botnets exploiting zero-day vulnerabilities and vendors delaying patch updates are nothing new. There are other details about Ttint that caught Netlab’s attention, as well as the interest of Radware researchers. Specifically, the Ttint IoT botnet was built on top of Mirai, a family of IoT malware that leaked online in 2016. Since its leak, there have been countless botnets that were offshoots of that original codebase.
Every botnet operator tried to innovate and add something different, but the Ttint IoT botnet appears to have borrowed something from each to create a variant of Mirai, more complex than any other. Ttint could signal the beginning of the maturation of general malicious IoT software and broader leverage into more advanced campaigns, according to Radware.
