logo

New Mirai botnet targets industrial routers with zero-day exploits

ID: 1866a433-78ef-55d5-867d-a506f2666ef8

STIX ID: report--1866a433-78ef-55d5-867d-a506f2666ef8

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2025-01-07

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A Mirai-based botnet discovered in February has evolved to use more than 20 public and custom exploits — including an observed zero-day (CVE-2024-12856 affecting Four-Faith industrial routers) — to compromise DVRs, routers, and smart home devices worldwide; it maintains ≈15,000 daily active nodes and performs short, high-intensity DDoS attacks exceeding 100 Gbps, using Telnet brute-force, custom UPX packing, and Mirai-derived command structures to propagate and execute attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.