HomeSecurityDark Mirai botnet targets popular TP-Link router RCE

Dark Mirai botnet targets RCE of popular TP-Link router

The Dark Mirai botnet , also known as MANGA , appears to be exploiting a new vulnerability in the TP-Link TL-WR840N EU V5 , a popular home and budget router, released in 2017.

Dark Mirai

See also: Google takes steps to “stop” the Glupteba botnet

The flaw (CVE-2021-41653) is caused by a vulnerable "host" variable, which an authenticated user can abuse to execute commands on the device.

TP-Link fixed the flaw by releasing the update TL-WR840N(EU)_V5_211109 on November 12, 2021. However, many users have not yet applied it, leaving their devices vulnerable.

The researcher who discovered the vulnerability published a proof of concept (PoC) of the RCE exploit.

According to a report by Fortinet, who were monitoring Dark Mirai activity, the botnet added this particular RCE to its arsenal just two weeks after TP-Link released the firmware update.

How is exploitation done?

In the case of Dark Mirai, malicious actors exploit the CVE-2021-41653 vulnerability to force devices to download and execute a malicious script, “tshit.sh,” which in turn downloads the main binary payloads via two requests.

Attackers still need authentication for this exploit to work, but if the user has left the device with the default credentials, exploiting the vulnerability becomes extremely easy.

See also: EwDoor Botnet: Targets AT&T network devices in US companies

Similar to the typical Mirai, MANGA detects the architecture of the infected machine and retrieves the corresponding payload.

It then blocks connections to commonly targeted ports to prevent other botnets from taking over the affected device.

Finally, the malware waits for a command from the C&C server to perform some form of DoS.

TP-Link

And Mirai may no longer exist, but its code has spawned many new botnets that cause large-scale problems on unsecured devices.

One of the most recent is “Moobot,” which exploits a command injection flaw in Hikvision products.

In August 2021, another Mirai-based botnet targeted a critical vulnerability in the SDK software used by a large number of Realtek-based devices.

See also: Moobot botnet spreads via vulnerability in Hikvision cameras

How will you protect yourself?

To secure your router from old and new variants of Mirai or any other botnet, implement the following:

  • Apply available firmware and security updates as soon as possible
  • Change the default administrator credentials with a strong password of 20 or more characters
  • Check your DNS settings regularly
  • Enable firewalls which are often disabled by default on home routers
  • Change your subnet address and enforce SSL on the admin page
  • Disable all remote management features
  • Disable UPnP and WPS if you are not using them
  • If your router is old and no longer supported by the vendor, replace it with a new one
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS