Juniper warns of Mirai botnet scanning for Session Smart routers
ID: 4c493a10-b85b-566c-92b0-06229c4cae84
STIX ID: report--4c493a10-b85b-566c-92b0-06229c4cae84
Feed Name: Bleeping Computer
Juniper Networks reported a Mirai-based malware campaign (first observed December 11) scanning the Internet for Session Smart routers that still use default credentials; compromised devices have been used to launch DDoS attacks. Juniper published IOCs (port scans, failed SSH logins, spikes in outbound traffic, erratic device behavior, known malicious IPs) and advised changing default passwords, applying firmware updates, monitoring logs, using IDS/firewalls, and reimaging any infected routers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
