Friday, May 2, 2025
HomeBotnetDigiEver IoT Devices Exploited To Deliver Mirai-based Malware

DigiEver IoT Devices Exploited To Deliver Mirai-based Malware

Published on

SIEM as a Service

Follow Us on Google News

A new Mirai-based botnet, “Hail Cock Botnet,” has been exploiting vulnerable IoT devices, including DigiEver DVRs and TP-Link devices with CVE-2023-1389.

The botnet, active since September 2024, leverages a variant of Mirai malware with enhanced encryption. 

A recent uptick in attacks targeting the URI /cgi-bin/cgi_main.cgi, exploiting an RCE vulnerability in DigiEver DS-2105 Pro devices, aligns with this campaign. While the vulnerability lacks a CVE, it was previously disclosed by Ta-Lun Yen of TXOne Research.

- Advertisement - Google News

The researcher identified vulnerable DigiEver DVRs exposed online and by analyzing the firmware, they discovered the `/cgi-bin/cgi_main.cgi` endpoint.

Exploiting this endpoint, they successfully executed arbitrary code on the vulnerable devices, potentially enabling remote control or data theft.

Endpoint with suspected vulnerability
Endpoint with suspected vulnerability

It was discovered targeting devices with known vulnerabilities and exploiting command injection flaws in DigiEver routers (/cfg_system_time.htm ntp parameter), TP-Link routers (/cgi-bin/luci;stok=/locale endpoint), and Tenda HG6 routers (/boaform/admin/formTracert). 

2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide

The botnet injects commands to download malicious scripts from remote servers, which then fetch and execute Mirai-based malware, where the attackers also target other vulnerabilities like CVE-2018-17532 using similar techniques.  

Contents of the “b.sh” shell script
Contents of the “b.sh” shell script

The Mirai-based malware samples analyzed employed a sophisticated multi-layer encryption scheme, combining XOR and ChaCha20 algorithms, which, while not entirely novel, demonstrates a clear evolution in the tactics of botnet operators. 

It’s ability to decrypt critical strings, such as botnet affiliation messages and default device credentials, highlights the increasing complexity of these threats and by leveraging advanced cryptographic methods, the malware aims to evade detection and hinder analysis efforts, thereby expanding its reach and impact. 

Decrypting with Salsa20 and ChaCha20
Decrypting with Salsa20 and ChaCha20

Akamai analyzed malware samples in a sandbox environment and observed persistence mechanisms, where the malware creates a cron job to download a shell script named “wget.sh” from “hailcocks.ru” and executes it, which likely establishes communication with the botnet’s C2 server at “kingstonwikkerink.dyn.” 

The malware also leaves a fingerprint in the console, with older versions announcing its affiliation to “hail cock botnet” and newer ones displaying a seemingly harmless message, “I just wanna look after my cats, man.”. 

Newer malware console output message
Newer malware console output message

As evidenced by the recent operation of the Hail Cock botnet, cybercriminals create botnets by utilizing obsolete hardware and firmware, where devices like the 10-year-old DigiEver DS-2105 Pro, lacking manufacturer support for security patches, are prime targets. 

To mitigate risks, users should upgrade vulnerable devices to newer, more secure models, especially when manufacturers cease providing updates. 

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Hundreds of Fortune 500 Companies Have Unknowingly Employed North Korean IT Operatives

North Korean nationals have successfully infiltrated the employee ranks of major global corporations at...

Stealthy New NodeJS Backdoor Infects Users Through CAPTCHA Verifications

Security researchers have uncovered a sophisticated malware campaign utilizing fake CAPTCHA verification screens to...

State-Sponsored Hacktivism on the Rise, Transforming the Cyber Threat Landscape

Global cybersecurity landscape is undergoing a significant transformation, as state-sponsored hacktivism gains traction amid...

NVIDIA Riva AI Speech Flaw Let Hackers Gain Unauthorized Access to Abuse GPU Resources & API keys

Researchers have uncovered significant security vulnerabilities in NVIDIA Riva, a breakthrough AI speech technology...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hundreds of Fortune 500 Companies Have Unknowingly Employed North Korean IT Operatives

North Korean nationals have successfully infiltrated the employee ranks of major global corporations at...

State-Sponsored Hacktivism on the Rise, Transforming the Cyber Threat Landscape

Global cybersecurity landscape is undergoing a significant transformation, as state-sponsored hacktivism gains traction amid...

Stealthy New NodeJS Backdoor Infects Users Through CAPTCHA Verifications

Security researchers have uncovered a sophisticated malware campaign utilizing fake CAPTCHA verification screens to...