Botnets created from the Mirai codebase continue to wreak havoc in the tech arena, with cyberattackers exploiting lax IoT security in widespread attacks.

See also: Phorpiex botnet: New Twizt variant makes it easier to steal cryptocurrencies
Computers and other connected devices, including IoT and NAS storage, are being compromised due to weak credentials, vulnerabilities, exploit kits, and other security weaknesses.
These systems are joined into a network of dependent devices that can be commanded to perform malicious activities.
The types of attacks commonly associated with botnets are Distributed Denial-of-Service (DDoS) attacks, brute-force leading to information theft and ransomware , and the covert installation of cryptocurrency mining software on vulnerable Internet-facing servers.
The most well-known, perhaps, is Mirai, which debuted with devastating DDoS attacks in 2016 against DNS provider Dyn.
See also: Dark Mirai botnet targets popular TP-Link router with RCE
Mirai's source code was subsequently released online, opening an avenue for variants to be created, including Okiru, Satori, and Masuta.
Despite the age of the original botnet, the code that underpins the network and the use of its code in mutated versions means that Mirai continues to pose a risk to organizations today.
On Tuesday, Intel 471 published a new report on the fragmentation of Mirai into new forms and a reported increase in attacks during 2020 and 2021 against IoT devices using these botnet variants.
As IoT device numbers are expected to reach approximately 30.9 billion by 2025, the team expects the threat – and overall power – of botnets to continue to expand.
Currently, Gafgyt and Mirai, along with several botnets based on Mirai code, such as BotenaGo, Echobot, Loli, Moonet, and Mozi, are used to target devices based primarily in Europe and North America.

See also: 300,000 MikroTik devices still vulnerable to botnets
Threat actors commonly use the following vulnerabilities in exploit kits to compromise IoT devices and increase the power of their networks:
- CVE-2018-4068, CVE-2018-4070, and CVE-2018-4071
- CVE-2019-12258, CVE-2019-12259, CVE-2019-12262, and CVE-2019-12264
- CVE-2019-12255, CVE-2019-12260, CVE-2019-12261, and CVE-2019-12263
- CVE-2021-28372
- CVE-2021-31251
Intel 471 recommends that organizations implement IoT device monitoring procedures, perform regular security audits, regularly change credentials and keys, and maintain regular patch application cycles.
Information source: zdnet.com
