HomeSecurityMooBot botnet targets unpatched D-Link routers

MooBot botnet targets unpatched D-Link routers

The MooBot botnet, a variant of the well-known Mirai malware botnet, has been used in attacks since early last month, targeting vulnerable D-Link routers.

MooBot was discovered by Fortinet analysts in December 2021. At the time, it was using a bug in Hikvision cameras to spread rapidly and recruit a large number of devices into its “ DDoS army .”

MooBot botnet

In the current attacks, MooBot appears to be targeting vulnerable D-Link routers. It is common for a botnet to change its targets as it continually searches for new groups of vulnerable devices.

See also: Zyxel: New NAS firmware fixes critical vulnerability

According to a report by researchers at Unit 42 Palo Alto Networks, the MooBot botnet is now exploiting the following critical issues on D-Link devices :

  • CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution vulnerability
  • CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability
  • CVE-2022-26258: D-Link Remote Command Execution vulnerability
  • CVE-2022-28958: D-Link Remote Command Execution vulnerability

D-Link has released updates security to address these vulnerabilities, but not all users have yet applied the patches. In particular, the last two vulnerabilities, which were disclosed in March and May, still affect many devices.

Operators of the MooBot botnet can easily exploit these vulnerabilities to perform remote code execution on targets and retrieve the malware binary using arbitrary commands.

D-Link routers MooBot botnet

After the malware decodes the hardcoded address from the configuration, the D-Link routers are registered in the threat actor's C2.

The trapped D-Links DDoS then participate in attacks against various targets, depending on what the operators of the MooBot botnet wish to achieve.

See also: Minecraft: The game most used by hackers to distribute malware

Typically, threat actors sell DDoS to others, so the botnet's capabilities are rented out to anyone interested in causing downtime and problems with sites and online services.

Users of compromised D-Link routers may notice decreased Internet speeds, responsiveness issues, router overheating, or unexplained changes to DNS configuration.

To protect your D-Link router from the MooBot botnet, apply available firmware updates immediately. If you are using an old and unsupported device, you should configure it to prevent remote access to the management panel.

See also: New Linux malware can evade detection

If a breach has already occurred, you should perform a reset from the corresponding physical button, change the administrator password , and then install the latest security updates from the vendor.

More details can be found in the Palo Alto Networks report

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS