logo

Botnet exploits GeoVision zero-day to install Mirai malware

ID: 2d7d6d88-5e10-5bca-a282-72a6d4d7e7cb

STIX ID: report--2d7d6d88-5e10-5bca-a282-72a6d4d7e7cb

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-11-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical zero-day OS command injection (CVE-2024-11120, CVSS 9.8) in end-of-life GeoVision devices is being actively exploited by a Mirai-like botnet to recruit roughly 17,000 internet-exposed devices—primarily for DDoS and cryptomining. Affected models (GV-VS12, GV-VS11, GV-DSP LPR V3, GV-LX4C V2/V3) are unsupported, leaving no vendor patches; recommended mitigations include device replacement, isolation on a dedicated subnet, resetting devices, changing default credentials, disabling remote access, and firewalling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.