HomeSecurityMoobot botnet spreads through vulnerability in Hikvision cameras

Moobot botnet spreads via vulnerability in Hikvision cameras

A Mirai-based botnet called “Moobot” is spreading aggressively by exploiting a critical command injection flaw in the webserver of several Hikvision products.

 Moobot botnet

See also: Google takes steps to “stop” the Glupteba botnet

Hikvision is a state-owned Chinese manufacturer of cameras and surveillance equipment that the US government has sanctioned for human rights abuses.

This vulnerability is tracked as CVE-2021-36260 and can be remotely exploited by sending specially crafted messages containing malicious commands.

Hikvision fixed the flaw in September 2021 with a firmware update (v 210628), but not all users rushed to apply the security update.

Fortinet reports that Moobot exploits this flaw to compromise unpatched devices and extract sensitive data from victims.

The infection process

Exploiting the flaw is quite simple, since it does not require authentication and can be triggered by sending a message to a vulnerable device that is publicly exposed.

Among the various payloads exploiting CVE-2021-36260, Fortinet found a downloader disguised as “macHelper”, which retrieves and executes Moobot with the “hikivision” parameter.

The malware also modifies basic commands such as “reboot” so that they do not work properly and will prevent the administrator from rebooting the compromised device.

Fortinet analysts identified several commonalities between Moobot and Mirai.

See also: EwDoor botnet: Targets AT&T network devices in US companies

In addition, Moobot includes some elements from Satori, a different variant of Mirai whose author was arrested and convicted in the summer of 2020.

It is important to highlight that this is not the first time Moobot has been detected, as researchers at Unit 42 first discovered it in February 2021.

However, the fact that the botnet continues to add new CVEs indicates that it is actively developing and enriching itself with new targeting capabilities.

 Moobot botnet

Moobot's goal is to embed the compromised device into a DDoS.

The C2 sends a SYN flood command along with the targeted IP address and port number to attack.

Other commands that the C2 server can send include 0x06 for UDP flood, 0x04 for ACK flood, and 0x05 for ACK+PUSH flood.

By examining the collected packet data, Fortinet was able to identify a Telegram channel that began offering DDoS services last August.

See also: School for hackers: Criminals teach lessons on botnets

Enrolling your device in “DDoS swarms” results in increased power consumption, accelerated wear and tear, and causes the device to become unresponsive.

The best way to protect your IoT devices from botnets is to apply available security updates as soon as possible and replace default credentials with strong passwords.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS