logo

'Mirai-like' botnet observed attacking EOL Zyxel NAS devices

ID: db4a0b13-46ba-5df2-b950-a1705bcaf96c

STIX ID: report--db4a0b13-46ba-5df2-b950-a1705bcaf96c

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-06-24

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers observed active exploitation attempts against end-of-life Zyxel NAS326 and NAS542 devices following public disclosure of three critical vulnerabilities (including CVE-2024-29973, an unauthenticated command injection). Shadowserver reported Mirai-like botnet activity attempting remote command execution; owners are advised to apply the vendor patches (V5.21(AAZF.17)C0 and V5.21(ABAG.14)C0) immediately or replace unsupported devices to mitigate compromise and botnet recruitment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.