logo

New Aquabotv3 botnet malware targets Mitel command injection flaw

ID: 8576fec2-8874-5749-98c3-a051d3417e2f

STIX ID: report--8576fec2-8874-5749-98c3-a051d3417e2f

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-01-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Akamai SIRT observed a new Mirai-derived botnet variant, Aquabotv3, actively exploiting CVE-2024-41710 in Mitel 6800/6900-series SIP phones to inject commands during boot, download architecture-specific payloads, establish persistence, and recruit devices into a DDoS botnet; the report explains the exploitation chain, propagation via multiple known IoT vulnerabilities and SSH/Telnet brute-forcing, and includes IoCs and detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.