Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Mirai Variant Murdoc_Botnet uses AVTECH IP cameras and Huawei routers
Global Security

Mirai Variant Murdoc_Botnet uses AVTECH IP cameras and Huawei routers

AdminBy AdminJanuary 21, 2025No Comments3 Mins Read
Murdoc_Botnet
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 21, 2025Ravi LakshmananBotnet / Vulnerability

Murdoc_Botnet

Cyber ​​security researchers have warned of a new large-scale campaign exploiting security flaws in AVTECH IP cameras and Huawei HG532 routers to connect devices to a Mirai botnet variant called Murdoc_Botnet.

The ongoing activity “demonstrates advanced capabilities by exploiting vulnerabilities to compromise devices and create extensive botnet networks,” Qualys security researcher Shilpesh Trivedi said in an analysis.

It is known that the company has been active since at least July 2024, p more than 1370 systems infected to date. Most of the cases of infection were located in Malaysia, Mexico, Thailand, Indonesia and Vietnam.

Cyber ​​security

Evidence shows that the botnet exploits known security flaws such as CVE-2017-17215 and CVE-2024-7029 to gain initial access to Internet of Things (IoT) devices and download the next-stage payload via a shell script.

The script, for its part, extracts the botnet malware and runs it depending on the processor architecture. The ultimate goal of these attacks is to make the botnet a weapon to carry out Distributed Denial of Service (DDoS) attacks.

The development comes weeks after the release of a Mirai botnet variant called gayfemboy found exploiting a recently discovered security flaw affecting Four-Faith industrial routers since early November 2024. In the middle of 2024. Neither does Akamai revealed that CVE-2024-7029 was used by abusers to include AVTECH devices in a botnet.

Murdoc_Botnet

Details emerged last week of another large-scale DDoS attack campaign targeting major Japanese corporations and banks from late 2024 using an IoT botnet created by exploiting vulnerabilities and weak credentials. Some of the other targets are centered around the US, Bahrain, Poland, Spain, Israel and Russia.

DDoS activity has been found to single out the telecommunications, technology, hosting, cloud computing, banking, gaming and financial services sectors. More than 55% of hacked devices are located in India, followed by South Africa, Brazil, Bangladesh and Kenya.

Cyber ​​security

“The botnet contains variants of malware derived from Mirai and BEGIN,” Trend Micro said. “Botnet commands include those that can include various DDoS attack techniques, update malware, and include proxy services.”

The attacks involve infiltrating IoT devices to deploy a bootloader malware that receives the actual payload, which then connects to a command and control (C2) server and waits for further instructions for DDoS attacks and other purposes.

To guard against such attacks, it is recommended to monitor suspicious processes, events, and network traffic caused by the execution of any untrusted binaries/scripts. It is also recommended to apply firmware updates and change the default username and password.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.