A new Mirai variant is targeting IoT devices - here's how to stay safe

Concept art representing cybersecurity principles
Nytt DDoS-rekord (Image credit: Shutterstock / ZinetroN)

A version of Mirai, called IZ1H9, has become the dominant variant of the dreaded botnet, infecting countless Linux devices and using them for different nefarious purposes.

According to Unit 42, the cybersecurity arm of Palo Alto Networks, which has been tracking IZ1H9 since August 2018, whose researchers revealed that since November 2021, a single threat actor has been actively deploying the variant. 

The campaign was only spotted in mid-April this year, and among other things, the threat actor was targeting endpoints that are already infected with Mirai, wiping previous iterations in order to only keep IZ1H9. 

Mirai botnet

“The malware also contains a function that ensures the device is running only one instance of this malware. If a botnet process already exists, the botnet client will terminate the current process and start a new one,” the researchers explained. The malware comes with a list of processes belonging not just to other botnet families, but also to other variants of Mirai. If it finds these processes running on the device, it will terminate them. 

IZ1H9 initially spreads through HTTP, SSH and Telnet protocols, the researchers added, saying that the best protection is to keep Linux devices patched and updated.

“To combat this threat, it is highly recommended that patches and updates are applied when possible,” the researchers concluded.

Botnets such as this one are usually used to mount Distributed Denial of Service (DDoS) attacks. DDoS is one of the most popular forms of attack out there, and it works by rendering a tool, or service (such as, for example, a website) inaccessible. In a DDoS attack, the attacker would flood the target server with so much bogus traffic that the server can’t handle it and eventually becomes clogged.

To get that kind of traffic, the attacker will need countless devices (such as Linux IoT devices, for example) to send traffic packets to the same address. 

Via: Infosecurity Magazine

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
TP-Link and NR routers targeted by worrying new botnet
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Industrial routers are being hit by zero-days from new Mirai botnets
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Dangerous new botnet targets webcams, routers across the world
DDoS Attack
Watch out, your office phone could be hijacked into a Mirai botnet
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
A display showing off the Google TV homepage, with icons for 1917, Scoob!, YouTube and Twitch (among others)
This dangerous malware botnet now covers 1.6 million Android TVs - find out if you're at risk
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras