Juniper Networks routers that use default passwords have been targeted by a Mirai botnet campaign, the networking products manufacturer is warning.
See also: DroidBot: Android malware steals credentials from banking apps

According to the company, several customers reported suspicious behavior on Juniper Smart Session Routers (SSR) a week ago, which was determined to be an infection with Mirai botnet malware.
All affected systems were using default credentials, were trapped in a botnet, and were used to launch distributed denial-of-service (DDoS) attacks against other systems.
"Any customer who does not follow recommended best practices and continues to use default passwords may be considered compromised, as default SSR passwords have been added to the virus database," Juniper notes in an advisory.
See also: New DDoS botnet campaign targets IoT devices
The malware scans the Internet for devices using default usernames and passwords, attempts to gain access to them, and then allows malicious actors to remotely execute various commands to perform malicious activities, including launching DDoS attacks.

Juniper advises organizations to monitor for unusual port scanning activity (such as connection attempts on TCP port 23), failed SSH connection attempts indicating brute force attacks, spikes in outbound traffic volume to unknown external IPs, unexpected device reboots, and erratic behavior and connections from known malicious IP addresses.
It is recommended that organizations change the default credentials on all routers and implement strong, unique passwords for each device, regularly check access logs to detect suspicious activity, use firewalls to block unauthorized access, monitor network behavior, and ensure that their devices are always up to date.
See also: Ngioweb botnet blocked by authorities
A botnet is a network of computers infected with malware and under the control of a cybercriminal, also known as a “botmaster”. These computers, known as “bots” or “zombies”, can be used for various malicious activities such as attacks, sending spam emails or data mining. Botnets often operate without the knowledge of the computer owner, posing a serious threat to the security of systems and data.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
