216.73.217.22

Mirai Bot now incorporating (malformed?) DrayTek Vigor Router Exploits

· Published 17/03/2025 05:39 · Modified 17/03/2025 10:08

Export JSON

Essential information

Published
17/03/2025 05:39
Modified
17/03/2025 10:08
Tags
2025-03-17 botnet draytek exploit firmware iot mirai router vigor vulnerability
Related entities
3 observables, 1 intrusion sets (apt), 9 techniques (mitre), 1 malware

Description

A report details the incorporation of exploits targeting routers into the . Previously disclosed vulnerabilities affecting approximately 700,000 devices are being exploited, with attacks focusing on the 'keyPath' and 'cvmcfgupload' parameters. A curious spike in malformed attempts, missing a dash in 'cgi-bin', has been observed. The attacks aim to upload and execute bot variants, primarily . The latest malformed attempts to download a multi-architecture bash script and the actual bot. String analysis of the bot reveals attempts to other vulnerabilities and likely includes a brute force component.

External references