HomeSecurityAquabotv3 botnet exploits vulnerability in Mitel phones

Aquabotv3 botnet exploits vulnerability in Mitel phones

Aquabotv3 , a new variant of the Aquabot botnet malware, exploits the CVE-2024-41710 vulnerability in Mitel SIP phones .

Aquabotv3 botnet malware Mitel phones

The malicious activity was discovered by researchers at Akamai, who report that this is the third Aquabot variant the team has identified.

The botnet malware first appeared in 2023 and later a second version was released with additional mechanisms persistence. The third variant, “Aquabotv3”, introduced a system that detects termination signals and sends the information to the command and control (C2) server.

Akamai comments that this mechanism for reporting kill attempts is unusual for botnets. It was likely added to provide operators with better tracking of attacks.

See also: New botnet exploits vulnerabilities in cameras and routers

Targeting Mitel phones

CVE-2024-41710 is a command injection vulnerability affecting Mitel 6800 Series, 6900 Series, and 6900w SIP phones. These devices are commonly used in corporate offices, businesses, government agencies, hospitals, educational institutions, hotels, and financial institutions.

This is a moderate severity vulnerability that allows an authenticated attacker, with administrator privileges, to perform an argument injection attack and result in arbitrary command execution.

Mitel has patched the vulnerability since July 17, 2024. Two weeks later, security researcher Kyle Burns published a proof-of-concept (PoC) exploit on GitHub. The use of this PoC by Aquabotv3 to exploit CVE-2024-41710 is the first documented case of this vulnerability being exploited. The fact that the attacks require authentication suggests that the botnet uses brute-forcing to gain initial access.

Attackers create an HTTP POST targeting the vulnerable 8021xsupport.html endpoint (responsible for authentication settings on Mitel SIP phones).

The application incorrectly processes user data, allowing malformed data to be imported into the phone's local configuration (/nvdata/etc/local.cfg).

See also: MikroTik botnet uses SPF DNS records to spread malware

By inserting line-ending characters (%dt → %0d), attackers manage to execute a remote shell script (bin.sh) from their server.

This script downloads and installs an Aquabot payload for the specified architecture (x86, ARM, MIPS, etc.), sets its execution permissions using 'chmod 777', and then cleans up any traces.

Aquabotv3 botnet exploits vulnerability in Mitel phones

Aquabotv3 botnet

Once persistence is ensured, Aquabotv3 connects to its C2 via TCP to receive instructions, attack commands, updates, or additional payloads.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It then attempts to infect other IoT devices using the Mitel exploit, CVE-2018-17532 (TP-Link), CVE-2023-26801 (IoT firmware RCE), CVE-2022-31137 (Web App RCE), Linksys E-series RCE, Hadoop YARN, and CVE-2018-10562 / CVE-2018-10561 (Dasan router bugs).

The Aquabotv3 botnet also attempts to steal default or weak SSH/Telnet credentials on unsecured devices on the same network.

Aquabotv3's goal is to recruit more devices to carry out DDoS attacks.

In the report you can find the indicators of compromise (IoC) related to Aquabotv3, as well as the Snort and YARA rules for detecting the malware.

See also: New botnet exploits vulnerabilities in cameras and routers

Botnet protection

To protect against this threat, it is important to software and operating system your device's. Botnet attacks often exploit known vulnerabilities.

It is also essential to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

Using strong passwords and changing them regularly is another way to protect yourself from Botnets. Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect your accounts.

Finally, information security training can be particularly useful. Understanding how botnet attacks work can help you identify and avoid attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS