Multi-Exploit IoT/Linux Botnets Mirai and Gafgyt Target Apache Struts, SonicWall
Last Update: Monday, September 10, 2018 : 17:46 (+4GMT)
September 10, 2018 - Dubai, UAE: Unit 42 has uncovered new variants of the well-known IoT botnets Mirai and Gafgyt. These are the IoT botnets associated with unprecedented Distributed Denial of Service attacks in November 2016 and since.
These variants are notable for two reasons:
• The new Mirai version targets the same Apache Struts vulnerability associated with the Equifax data breach in 2017.
• The new Gafgyt version targets a newly disclosed vulnerability affecting older, unsupported versions of SonicWall’s Global Management System (GMS).
These developments suggest these IOT botnets are increasingly targeting enterprise devices with outdated versions.
All organizations should ensure they keep not only their systems up-to-date and patched, but also their IoT devices. For Palo Alto Networks customers, WidlFire detects all related samples with malicious verdicts. Additional protections are noted in the conclusion below.
Research:
On September 7, 2018, Unit 42 found samples of a Mirai variant that incorporates exploits targeting 16 separate vulnerabilities. While the use of multiple exploits within a single sample of Mirai has been observed in the past, this is the first known instance of Mirai targeting a vulnerability in Apache Struts.
In addition, Unit 42 found the domain that is currently hosting these Mirai samples previously resolved to a different IP address during the month of August. During that time this IP was intermittently hosting samples of Gafgyt that incorporated an exploit against CVE-2018-9866 a SonicWall vulnerability affecting older versions of SonicWall Global Management System (GMS). SonciWall has been notified of this development.
The incorporation of exploits targeting Apache Struts and SonicWall by these IoT/Linux botnets could indicate a larger movement from consumer device targets to enterprise targets.
Previous Article
Oman Arab Bank Selects Trend Micro to Protect its IT Environment
Next Article
HP launches industry's first print security bug bounty program
Most Viewed – Last 30 Days
- Fresh Skin, Glazed Brows: Benefit Cosmetics Has Your Spring Beauty Mood Covere... [2473-Views]
- Beauty Spring Cleaning with Benefit Cosmetics!... [1843-Views]
- Lucky Day Draw Records Second Grand Prize Win as Nepalese Player Claims AED 30... [1398-Views]
- 'Make it a Dubai Summer' with the Most Value-Packed Edition Ever of DSS: Enjoy... [1237-Views]
- EU261 Reform Misses the Mark on Delays and Competitiveness... [1219-Views]
- Emirati AI Experts Prepare to Lead Implementation of UAE AI Strategy 2031... [1116-Views]
- UAE Participates in EBRD Board of Governors Meeting and Reaffirms Support for ... [1059-Views]
- ãÌãæÚÉ ÇáÎáíÌ áÇÓÊÑÌÇÚ ÇáÃãæÇá ÇÓÊÑÏÇÏ ÎÓÇÆÑ ÇáÊÏÇæá ÈÎÈÑÉ ... [992-Views]
- Ministry of Finance Unveils UAE's First Sovereign Retail T- Sukuk Investment O... [975-Views]
- Riyadh Air Opens Ticket Sales for Daily Service between Dubai, UAE and Riyadh,... [948-Views]
- Danube Properties Expands UK Presence with New London Office, Eyes Wider Europ... [906-Views]
- Under the directives of Mohammed bin Rashid Dubai Humanitarian facilitates se... [891-Views]
- Sports Coordination Council discusses sports representation framework, governa... [870-Views]
- Mohammed Bin Rashid Library Emphasises Role of Families in Building Children's... [869-Views]
- UAEREP Kicks Off AI-Driven Research Project on Next-Generation Cloud Seeding M... [866-Views]
- Emirati Developer GAF Property Shapes a New Residential Experience with Flow25... [860-Views]
- Umm Al Quwain Free Trade Zone (UAQ FTZ) Launches Company Migration Programme t... [846-Views]
- Etihad Rail Supports the Fishing Sector through the Rail Transport of Fresh Fi... [817-Views]
- Under supervision of Smart and Autonomous Systems Council, Abu Dhabi Investmen... [803-Views]
- Malabar Gold & Diamonds continues its expansion in North America: Launches 8th... [795-Views]



