216.73.217.22

Mass Campaign of Murdoc Botnet Mirai: A New Variant of Corona Mirai

· Published 22/01/2025 09:12 · Modified 22/01/2025 10:16

Export JSON

Essential information

Published
22/01/2025 09:12
Modified
22/01/2025 10:16
Tags
2025-01-22 botnet iot mirai murdoc botnet
Related entities
1 intrusion sets (apt), 15 techniques (mitre), 2 malware, 4 others

Description

The Qualys Threat Research Unit has uncovered a large-scale operation within the campaign, dubbed . This variant exploits vulnerabilities in AVTECH Cameras and Huawei HG532 routers, demonstrating enhanced capabilities to compromise devices and establish expansive networks. The campaign, which began in July 2024, uses ELF file and Shell Script execution to deploy the sample. Over 1300 IPs were found active, with 100+ distinct sets of servers distributing the malware. The targets vulnerable devices using existing exploits like CVE-2024-7029 and CVE-2017-17215. Affected countries include Malaysia, Thailand, Mexico, and Indonesia. The malware uses shell scripts to fetch, execute, and remove payloads on compromised devices.

External references