Persirai Botnet: 120,000 Hacked Cameras Phoning Home To Iran
ID: 3bcf35ca-7482-5e3e-8afe-939e77ccf320
STIX ID: report--3bcf35ca-7482-5e3e-8afe-939e77ccf320
Feed Name: Security Ledger
Threat Score
Trend Micro reported discovery of the Persirai botnet: approximately 120,000 IP cameras across more than 1,000 models are being compromised by abusing UPnP and a known firmware vulnerability to deliver in-memory malware that phones home to command-and-control servers (reported to be in Iran); the hijacked cameras can be used for DDoS and to propagate further compromises, with default passwords and lack of vendor patches cited as contributing factors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
