Vulnerabilities

Moobot botnet spreads via Hikvision camera vulnerability

0

The Mirai-based Moobot botnet is spreading rapidly by exploiting a critical command injection vulnerability dubbed as CVE-2021-36260, in the webserver of several Hikvision products.

The Moobot was first documented by Palo Alto Unit 42 researchers in February 2021. The recent attacks indicate that its authors are enhancing their malware.

The critical flaw affects over 70 Hikvision camera and NVR models that allows attackers to take over the devices. The unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware was discovered by a security researcher who goes by the moniker “Watchful IP.”

After compromising the IP camera, the hacked device can be used to access internal networks posing a risk to the infrastructure that uses the devices.

The exploitation of the issue does not require user interaction, the attacker only needs access to the http(s) server port (typically 80/443).

It has been found that every firmware developed since 2016 has been tested and are vulnerable.

According to Hikvision, the vulnerability is due to insufficient input validation and can be exploited by sending specially crafted messages to vulnerable devices.

According to the company, the attacker can exploit the flaw only if he has access to the device network or the device has direct interface with the Internet.

On reporting the vulnerability, firmware updates was released by the company on September 19.

Fortinet researchers stated that the vulnerability was exploited by botnet operators to extract sensitive data from unpatched devices.

The researchers spotted a downloader for the Moobot malware with the “hikivision” parameter, it saves final payload as “macHelper.”

The malware also modifies basic commands like “reboot” to prevent an administrator from rebooting the infected device.

Fortinet researchers found similarities between Moobot and Mirai, and that Moobot borrows some elements from the Satori botnet.

Moobot is a DDoS botnet that supports multiple attack methods. The analysis of captured packet data, allowed Fortinet researchers to track down a Telegram channel used to advertise DDoS services since August.

Fortinet suggests that the users must upgrade affected devices immediately as well as apply FortiGuard protection.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Hackers infect random WordPress plugins to steal credit cards

Previous article

BlackCat ransomware, a sophisticated malware written in Rust

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *