logo

Why is my Mitel phone DDoSing strangers? Oh, it was roped into a new Mirai botnet

ID: 4e1cb58a-80f8-55f7-9199-ab0046cd2e92

STIX ID: report--4e1cb58a-80f8-55f7-9199-ab0046cd2e92

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2025-01-29

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Akamai's Security Intelligence team identified Aquabotv3, a new Mirai-based botnet variant actively exploiting Mitel phone command-injection vulnerability CVE-2024-41710 (affecting Mitel 6800/6900 series) to install Mirai malware and form DDoS-capable botnets; the strain introduces a novel capability to report received kill signals back to its C2. Akamai observed exploit attempts matching a published PoC in their honeypots, and the malware also spreads via several other known RCE vulnerabilities and architectures (x86, ARM). Mitel issued a patch in July for affected firmware, and default/weak credentials on IP phones increase exploitation risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.