HomeSecurityIvanti vulnerabilities used to deploy Mirai botnet

Ivanti vulnerabilities used to deploy Mirai botnet

Two vulnerabilities recently discovered in Ivanti Connect Secure (ICS) appear to be used to deploy the infamous Mirai botnet.

Mirai botnet Ivanti vulnerabilities

According to research by Juniper Threat Labs, vulnerabilities CVE-2023-46805 and CVE-2024-21887 have been used to deliver the botnet payload. The first vulnerability allows authentication bypass, while the second is a command injection vulnerability. Attackers can combine the two flaws to execute code and take control of unpatched instances.

In the attack chain identified, the Ivanti vulnerability CVE-2023-46805 was used to gain access to the “/api/v1/license/key-status/;” endpoint (which is vulnerable to command injection) and to inject the Mirai botnet payload.

See also: Goldoon Botnet targets D-Link Routers

Regarding the exploitation of the CVE-2024-21887 vulnerability, it is activated through a request to “/api/v1/totp/user-backup-code/” for the deployment of the malicious software.

"This sequence of commands attempts to delete files, downloads a script from a remote server, sets executable permissions, and executes the script, potentially leading to an infected system," said security researcher Kashinath T Pattan.

The shell script, in turn, downloads the Mirai botnet malware from an IP address controlled by the attackers (“192.3.152[.]183”).

According to the researcher, the delivery of the Mirai botnet through these vulnerabilities “highlights the ever-evolving cyberthreat landscape.”

See also: US: Charges against Moldova for operating botnet

The Mirai infection also means that other harmful malware and ransomware will be developed.

Ivanti vulnerabilities used to deploy Mirai botnet
Ivanti vulnerabilities used to deploy Mirai botnet

Protection against botnet malware

To protect yourself from Botnets, it is important to keep your device's software and operating system up to date. attacks exploit known vulnerabilities (as in this case).

Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

See also: Multiple botnets exploit TP-Link flaws

Using strong passwords and changing them regularly is another way to protect yourself from Botnet (e.g. Mirai). Botnet attacks often try to guess passwords , so using strong passwords and changing them regularly can help protect your accounts.

Finally, information security training can be particularly useful. Understanding how attacks work and the techniques they use can help you identify and avoid attacks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS