Menu
Hackers create more IoT botnets with Mirai source code

Hackers create more IoT botnets with Mirai source code

The total number of IoT devices infected with the Mirai malware has reached 493,000

Malware that can build botnets out of IoT products has gone on to infect twice as many devices after its source code was publicly released.

The total number of IoT devices infected with the Mirai malware has reached 493,000, up from 213,000 bots before the source code was disclosed around Oct. 1, according to internet backbone provider Level 3 Communications.

"The true number of actual bots may be higher," Level 3 said in a Tuesday blog post.

Hackers have been taking advantage of the Mirai malware's source code, following its role in launching a massive DDOS (distributed denial-of-service) attack that took down the website of cybersecurity reporter Brian Krebs.

Unlike other botnets that rely on PCs, however, Mirai works by infecting internet-connected devices such as cameras and DVRs that come with weak default usernames and passwords.

Since Mirai's source code was released, hackers have been developing new variants of the malware, according to Level 3. It has identified four additional command-and-control servers associated with Mirai activity coming online this month.

About half of the infected bots Level 3 has observed resided in either the U.S. or Brazil. More than 80 percent of them were DVR devices.

Many of the DDOS attacks launched by Mirai botnets are used against game servers and residential IP addresses, Level 3 said.

"We have observed several attacks using more than 100 Gbps" of traffic, it said. "Large armies of bots participated in attacks, with several using over 100,000 bots against the same victim."

A few vendors that produce devices vulnerable to Mirai are encouraging their customers to take steps to mitigate the risk. Sierra Wireless, for instance, has issued a bulletin, advising users to reboot one of their products and change the default password.

However, it's unclear if other vendors are taking any steps to do the same. Security firm Flashpoint has identified Chinese company Hangzhou Xiongmai Technology as another maker of DVR products susceptible to the Mirai malware.

Potentially, half a million devices from the company are vulnerable partly due to their unchangeable default passwords, according to Flashpoint. But Xiongmai has not commented on the matter.


Follow Us

Join the newsletter!

Or
Error: Please check your email address.

Featured

Slideshows

Bumper channel crowd kicks off first After Hours of 2018

Bumper channel crowd kicks off first After Hours of 2018

After Hours made a welcome return to the channel social calendar with a bumper crowd of partners, distributors and vendors descending on The Jefferson in Auckland to kick-start 2018. Photos by Gino Demeer.

Bumper channel crowd kicks off first After Hours of 2018
Looking back at the top 15 M&A deals in NZ during 2017

Looking back at the top 15 M&A deals in NZ during 2017

In 2017, merger and acquisitions fever reached new heights in New Zealand, with a host of big name deals dominating the headlines. Reseller News recaps the most important transactions of the Kiwi channel during the past 12 months.

Looking back at the top 15 M&A deals in NZ during 2017
Kiwi channel closes 2017 with After Hours

Kiwi channel closes 2017 with After Hours

The channel in New Zealand came together to celebrate the close of 2017, as the final After Hours played out in front of a bumper Auckland crowd.

Kiwi channel closes 2017 with After Hours
Show Comments