Researchers discovered the Wicked botnet, which is a Mirai variant that uses multiple exploits to target vulnerable IoT devices, including Netgear routers and CCTV video cameras.
|
Scooped by
Judy Curtis / SIPR
onto Security & the Internet of Things: IoT, OT, IIoT May 30, 2018 11:43 AM
|
The Wicked botnet scans ports 8080, 8443, 80 and 81and it will try to exploit the device once a connection is established. The exploits used depend on which port the botnet connects to for specific devices.
Targeted devices include flawed Netgear routers -- some of which were also used by the Reaper botnet -- and closed-circuit video cameras that have a remote code execution flaw. One exploit doesn't target a device, but instead targets compromised web servers with malicious invoker shells that are already installed.