HomeSecurityIZ1H9 DDoS botnet: Mirai variant targets routers

IZ1H9 DDoS botnet: Mirai variant targets routers

A DDoS malware botnet based on the well-known Mirai and known as IZ1H9has added thirteen new payloads to attack Linux-based routers and routers from D-Link, Zyxel, TP-Link, TOTOLINK and others.

Fortinet researchers noticed an increase in the exploitation rate during the first week of September. In fact, they said they detected tens of thousands of attempts to exploit vulnerable devices.

IZ1H9 Mirai botnet

The IZ1H9 botnet compromises devices (vulnerable routers) to integrate them into the DDoS network and then executes DDoS attacks on specific targets.

The more devices that are compromised, the larger and more powerful the botnet becomes.

See also: P2PInfect botnet experiences a period of high activity

In the case of IZ1H9, Fortinet says it is using exploits for the following bugs, dating from 2015 to 2023:

  • D–Link devices: CVE-2015-1187, CVE-2016-20017, CVE-2020-25506, CVE-2021-45382
  • Netis WF2419: CVE-2019-19356
  • Sunhillo SureLine (versions before 8.7.0.1.1): CVE-2021-36380
  • Geutebruck products: CVE-2021-33544, CVE-2021-33548, CVE-2021-33549, CVE-2021-33550, CVE-2021-33551, CVE-2021-33552, CVE-2021-33553, CVE-2021-33554
  • Yealink Device Management (DM) 3.6.0.20: CVE-2021-27561, CVE-2021-27562
  • Zyxel EMG3525/VMG1312 (before V5.50): CVE not specified but targets /bin/zhttpd/ component vulnerability of Zyxel devices
  • TP-Link Archer AX21 (AX1800): CVE-2023-1389
  • Korenix JetWave wireless AP: CVE-2023-23295
  • TOTOLINK routers: CVE-2022-40475, CVE-2022-25080, CVE-2022-25079, CVE-2022-25081, CVE-2022-25082, CVE-2022-25078, CVE-2022-25084, CVE-2022-25077, CVE-2022-25076, CVE-2022-38511, CVE-2022-25075, CVE-2022-25083

The Mirai-based botnet also targets another vulnerability related to the “/cgi-bin/login.cgi” route, with potential impacts on the Prolink PRC2402M router.

How is the attack carried out?

After exploiting one of the aforementioned CVEs, an IZ1H9 payload is embedded on the device. This contains a command to retrieve a shell script downloader named “l.sh”, from a specified URL.

After execution, the script deletes log files to hide malicious activity. It then retrieves bot clients designed for different system.

See also: Mirai botnet: New version infects Android TV boxes for profit

DDoS botnets

Finally, the script modifies the iptables rules to block connections to specific ports and make it difficult to remove the malware from the device.

Once all this is done, the IZ1H9 DDoS botnet establishes communication with the C2 (command and control) server and waits for commands. The supported commands relate to the type of DDoS attack to be executed.

According to Fortinet, IZ1H9 also has a data with hardcoded credentials for brute-force attacks. These attacks can be useful for spreading to neighboring devices.

This new variant of the Mirai botnet now uses 13 additional exploits, significantly increasing the number of routers and IoT devices it can recruit to expand the botnet.

How can we protect ourselves? 

This begs the question: is there a way to protect ourselves from this threat? Prevention is everything, and at the heart of this protection approach is regularly updating our routers and devices in general. Of course, it is not always possible to keep software up to date or apply patches for all the exploits that are out there, but it is important to promptly apply all available updates to at least avoid vulnerabilities that are already known and have been fixed. 

See also: HTTP/2 Rapid Reset: New DDoS attack exploits as zero-day

Vigilance is the key 

Additionally, we cannot underestimate the importance of vigilance. It is important to regularly monitor for any suspicious movements on network . Understanding and recognizing the signs of a potential Mirai attack can be an important first line of defense.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS