Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » New Aquabot Botnet exploits Cve-2024-41710 in Mitel phones for DDOS attacks
Global Security

New Aquabot Botnet exploits Cve-2024-41710 in Mitel phones for DDOS attacks

AdminBy AdminJanuary 30, 2025No Comments3 Mins Read
Aquabot Botnet
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 30, 2025Red LakshmananVulnerability / security IoT

Aquabot Botnet

A Mirai botnet the option that is named Aquatato An active attempt to use medium -speed security deficiency has been noted that Mitel’s phones to go into the network capable of installing common service refusal attacks (DDOS).

Vulnerability in question Cve-2024-41710 (CVSS assessment: 6.8), the case of team introduction during the download process, which can allow malicious actors to perform arbitrary commands in the context of the phone.

This affects the Mitel 6800 series, the 6900 series, the 6900 W SIP series and the Mitel 6970 conference. It was address In mid -July 2024 mitteels. Publicly available In August.

Cybersecurity

Outside the CVE-2024-41710, some other vulnerabilities focused on the Botnet Remote Code Fulfillment, focused on Linksys E-Series device.

“Aquabot-it’s botnet, which was built as part of Mirai with the ultimate purpose of distributed service (DDOS),” Akama Kyle Lofton and Larry Cashdolar. – Note. “It was know Since November 2023 “

Web Infrastructure said an active operation against CVE-2024-41710 has been revealed since the beginning of January 2025, and the attacks reflect a “useful load, almost identical to POC to expand the Botnet malicious software.

The attack involves the execution of the shell script, which in turn uses the “WGET” command to obtain Aquabot for different processor architectures.

The Aquabot Mirai variant, noticed in the attack, was evaluated by the third malware. However, sending this information has not been revealed that it does not call any response from the server to date.

This new version, in addition to launching the C2 communication when detecting certain signals, is renamed “httpd.x86” to avoid attracting attention and programmed to stop the processes that meet certain requirements, such as local shells. It is suspected that the features of signaling is probably included to create more hidden options or reveal harmful activity from competing botnet.

There are several evidence that suggests that the threats behind the Aquabot are offering a network of violated hosts as a DDOS service on Telegram under firewall cursinq cursinq, servicees Eye and The Eye Botnet.

Cybersecurity

Develop-is a sign that Mirai continues to build a wide range of devices connected to the Internet that often do not have proper security features, either reached the end of life or remain available with default configuration and passwords, making them ripe with low fruit For operation and key channel for DDOS attacks.

“The threatening actors usually claim that Botnet is only used for DDOS testing to try to mislead researchers or law enforcement,” the researchers said.

“The threatening actors will claim that it is just a POC or something educational, but a deeper analysis shows that they actually advertise DDOS as a service, or owners boast their own botnets on telegram.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.