logo

The Worm (Re)Turns, Targets Embedded Linux AirOS

ID: f0e9ed12-093e-5c60-9c26-895ec2548518

STIX ID: report--f0e9ed12-093e-5c60-9c26-895ec2548518

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2016-05-22

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

A self-replicating worm is exploiting a known, patched AirOS firmware vulnerability to infect Ubiquiti airMAX and related devices worldwide. The malware uploads files, creates a backdoor account (username “mother”), blocks admin access, installs persistence to run on reboot, and scans for other AirOS devices to propagate; despite a July 2015 patch many devices remained unpatched, leading to reports of thousands of infected devices in regions such as Spain and Brazil.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.