HomeSecurityMirai botnets exploit lax IoT security

Mirai botnets exploit lax IoT security

Botnets created from the Mirai codebase continue to wreak havoc in the tech arena, with cyberattackers exploiting lax IoT security in widespread attacks.

Mirai botnet

See also: Phorpiex botnet: New Twizt variant makes it easier to steal cryptocurrencies

Computers and other connected devices, including IoT and NAS storage, are being compromised due to weak credentials, vulnerabilities, exploit kits, and other security weaknesses.

These systems are joined into a network of dependent devices that can be commanded to perform malicious activities.

The types of attacks commonly associated with botnets are Distributed Denial-of-Service (DDoS) attacks, brute-force leading to information theft and ransomware , and the covert installation of cryptocurrency mining software on vulnerable Internet-facing servers.

The most well-known, perhaps, is Mirai, which debuted with devastating DDoS attacks in 2016 against DNS provider Dyn.

See also: Dark Mirai botnet targets popular TP-Link router with RCE

Mirai's source code was subsequently released online, opening an avenue for variants to be created, including Okiru, Satori, and Masuta.

Despite the age of the original botnet, the code that underpins the network and the use of its code in mutated versions means that Mirai continues to pose a risk to organizations today.

On Tuesday, Intel 471 published a new report on the fragmentation of Mirai into new forms and a reported increase in attacks during 2020 and 2021 against IoT devices using these botnet variants.

As IoT device numbers are expected to reach approximately 30.9 billion by 2025, the team expects the threat – and overall power – of botnets to continue to expand.

Currently, Gafgyt and Mirai, along with several botnets based on Mirai code, such as BotenaGo, Echobot, Loli, Moonet, and Mozi, are used to target devices based primarily in Europe and North America.

Mirai botnets exploit lax IoT security

See also: 300,000 MikroTik devices still vulnerable to botnets

Threat actors commonly use the following vulnerabilities in exploit kits to compromise IoT devices and increase the power of their networks:

  • CVE-2018-4068, CVE-2018-4070, and CVE-2018-4071
  • CVE-2019-12258, CVE-2019-12259, CVE-2019-12262, and CVE-2019-12264
  • CVE-2019-12255, CVE-2019-12260, CVE-2019-12261, and CVE-2019-12263
  • CVE-2021-28372
  • CVE-2021-31251

Intel 471 recommends that organizations implement IoT device monitoring procedures, perform regular security audits, regularly change credentials and keys, and maintain regular patch application cycles.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS