Security researchers observed Moobot and other botnets attempting to exploit a zero-day vulnerability in order to compromise fiber routers.

The Network Security Research Lab at 360 detected Moobot abusing the zero-day vulnerability beginning in late February 2020. The exploit involved two steps at the time of analysis. For it to work, digital attackers needed to leverage another vulnerability along with the zero-day flaw.

Not all threat actors who attempted to exploit the zero-day weakness realized the need for another security flaw. This fact became evident in mid-March when the Gafgyt malware tried using a Netlink GPON router remote command execution vulnerability PoC released by Exploit Database, which matched the vulnerability abused by Moobot a month earlier. Gafgyt conducted an internet-wide scan using the exploit, but because it did not leverage another vulnerability, the scan mostly failed.

The same thing happened when digital attackers attempted to spread the Fbot botnet using the flaw. Without the incorporation of another vulnerability, many of the exploit attempts failed.

A Look Back at Moobot’s Recent Activity

Security professionals with the Network Security Research Lab at 360 first came across Moobot back in September 2019. At that time, the team observed the malware using Mirai’s scanning technique to scour the internet for vulnerable devices. It was just a few months later when Network 360 reached out to the equipment manufacturer LILIN after observing multiple attack groups exploiting zero-day vulnerabilities in its DVRs to spread Moobot and other botnets.

How to Defend Against Zero-Day Vulnerabilities

Infosec personnel can help defend their organizations against zero-day vulnerabilities by checking for firmware updates that affect their routers. This process will likely involve registering their devices and signing up for email alerts. Companies should also consider deploying tools that use artificial intelligence (AI) for the purpose of detecting malicious behaviors, such as attempted exploitation of flaws that have yet to be publicly disclosed.

More from

Is It Time to Start Hiding Your Work Emails?

In this digital age, it is increasingly important for businesses to be aware of their online presence and data security. Many companies have already implemented measures such as two-factor authentication and strong password policies – but there is still a great deal of exposure regarding email visibility. It should come as no surprise that cyber criminals are always looking for ways to gain access to sensitive information. Unfortunately, emails are a particularly easy target as many businesses do not encrypt…

2022 Industry Threat Recap: Finance and Insurance

The finance and insurance sector proved a top target for cybersecurity threats in 2022. The IBM Security X-Force Threat Intelligence Index 2023 found this sector ranked as the second most attacked, with 18.9% of X-Force incident response cases. If, as Shakespeare tells us, past is prologue, this sector will likely remain a target in 2023. Finance and insurance ranked as the most attacked sector from 2016 to 2020, with the manufacturing sector the most attacked in 2021 and 2022. What…

X-Force Prevents Zero Day from Going Anywhere

This blog was made possible through contributions from Fred Chidsey and Joseph Lozowski. The 2023 X-Force Threat Intelligence Index shows that vulnerability discovery has rapidly increased year-over-year and according to X-Force’s cumulative vulnerability and exploit database, only 3% of vulnerabilities are associated with a zero day. X-Force often observes zero-day exploitation on Internet-facing systems as a vector for initial access however, X-Force has also observed zero-day attacks leveraged by attackers to accomplish their goals and objectives after initial access was…

And Stay Out! Blocking Backdoor Break-Ins

Backdoor access was the most common threat vector in 2022. According to the 2023 IBM Security X-Force Threat Intelligence Index, 21% of incidents saw the use of backdoors, outpacing perennial compromise favorite ransomware, which came in at just 17%. The good news? In 67% of backdoor attacks, defenders were able to disrupt attacker efforts and lock digital doorways before ransomware payloads were deployed. The not-so-great news? With backdoor access now available at a bargain price on the dark web, businesses…