Botnet Leverages Hikvision Critical Vulnerability For DDoS Attacks And "Extracting Sensitive Data From Victims"

Published Dec 09, 2021 12:21 PM

A Mirai-based botnet, Moobot, is targeting devices left vulnerable following Hikvision's 9.8 critical vulnerability in September 2021. The attacks include "extracting sensitive data from victims", which Hikvision argued recently was "literally impossible".

IPVM Image

Cybersecurity concerns are a long-standing issue for Hikvision. The 2019 NDAA banned federal use of its products and the US government is planning to ban further FCC authorizations.

In this report, we look at the Moobot botnet, how it works, what devices are impacted, and Hikvision's response.

**********

**** ********* ************* ** ********** ************ for ********* ***** ** ***** **** control ** *** ******,** *** ********** *** ********** ** explained:

**** ******* ** ******** ** **** full ******* ** ****** **** ** unrestricted **** *****, ***** ** *** more ****** **** **** *** ***** of *** ****** *** ** **** are ********** ** * ******* “********* shell” (***) ***** ******* ***** ** a ********** *** ** *******, ****** informational ********.

Discovered ** ********

************* ************ ******* *** ********* *** ******** of ****** ** **** **** ****. ***** *********'* ********** *****-****-*****, ******** ********* ** ********* ********** signature *** *** *************, ********* ********* behavior ********** *** ************* ** *** process.

How ** *****

********* ******* *** ********* ***** ***-****-*****, allowing ********* ** *** ******** ******* authorization. ** **** ****, *** ******** sends ******** ** ********* **** **** a ***, ***** ****:

IPVM Image

*** ******* ***** ******* "*********" *** then ******** *** **** **** * downloader **** ******** *** **** *** Moobot ******.

********'* ************ ***** *** ******* *******:

IPVM Image

**** ********, ********* ******* *** ** used, ***** **** ***** ******** *******, to ******* **** *******. ****** * DDoS ******, *** ****** ** *********** with ***** ******** **** *** ****** and *** *** ****** ********** ********.

************, *********** ** ******** ***** **** a **** ******* ******** ** ******* the *** ** ***** ******* ** telegram.

"Extracting ********* **** **** *******"

** ******** ** ********* ******* ** other *******, *** ******

** ******** ******** ******** ********** ** leverage **** ************* ** ******* *** status ** ******* **extracting ********* **** **** *******. One payload in particular caught our attention. It tries to drop a downloader that exhibits ********* ******** [emphasis added]

***** ******** **** *** ****** **** specific **** ** ***** *********, **** is *************** *** ** ******** ** do ******* *** ************* ***** **** control **** *** ******.

"Literally **********," **** *********

******* **** ********* *********, *********'* ***/*** Fred ********** **** ******* **** **** that **** ******* ***** ** ********* impossible, ********:

*** ***-***** *** *** ***** ******* are *********** *** *** ****/***** ******* they ********. ** ***** *****, ****’** the **** ********** *** ******* *** data *** ******* *** ***** *******, which ** ******* ******** ** ** kept *******. ****** ****** ** ***** footage ** ***** ******* ** ********** without *** ******* ** *** ***-****.

**** ***** ******** *********'* ******** ****:

Affected *******

** *** ********, ***** *** * vast ****** ** ********* ******* ******** accessible **** *** ** *********. ***** the ***** ****** ** ********* ******* being ********* ** ****** ** *******, Shodan ***** *+ ******* ********* ******* available ** *** ****** ********, ****** this **** *** ******* ****/**********.

IPVM Image

***** *** ******* ** ******* **** were ******** ** **** ******** *************, including **** *******, ****, *********, ***. before ****/**** ****, ** ** ******** that ****** ***** ******* ******** ** thousands ** **** * ******* *********** Hikvision *******.

Moobot *** **** ********* *******

**** **** ****** ** *** * new ****** *** ******* ****** ********'* discovery ** ********* ******* ***** *********. It *** ***** ******** ****** ****, ********* ********/***** ****** ******* *** IoT ********.

** ** ******* **** *** **** devices ****** ********, *** *** ******** of *********** * ******* ** **** vulnerable ********* ******* ***** ** **** larger *** **** *********.

Surveillance ****** *******

***** ******* ********** ********** ************ ******* have **** **** ** ******* ****-******* DDoS *******, ************ **************** ** ****** *******'* ******** *******. ***** * *****-***** *******,********, *** ***** ********** ********* ********/*** cameras.

***** *** ********* ** ****** ******* million ******* ** *** ******** ****. Moobot *** *********** ****** **** ****, given *** ***** ** ********* ******* impacted.

************, *****-***** ******* *** ****-***********, ******* that **** ************ **** *** ********** vulnerable *******. ** ******** *** ** in ***** ********:

******** * ***** *** **** ******** to ******* **** *************, **** *** botnet **** ***** **** ******* *** a ********** *** *****.

**** ***** ******** ******* ******** ** reducing *** ******'* ****/******.

Hikvision ******** ** *******

*********'* ****** ************** *** ** ************ **** **************** ****** **** **** ******* ** comment.

************ ************* ********* ** ******* ** ******* ***** susceptible ** ****** *** **** ******* being *********, ******** ********* *** ***** users ** ********** *** ******** ** CVE-2021-36260.

Hikvision **** ********** ************** *****

********* ********* ** ************* ********** *** "***** *** ****** access" ** "*** ** *** ********* fail":

** *** ** *** ********* **** to **** *** ***** ** *****, who **** ** **** * ***** and ****** ****** ** *** ********* port ******* ** *** ****** ******* the ********, ***** *** **** ** choose *** *********** '**** **********' ******.

************************* ***** *** *********** ** *** surveys, **** **** ********** ***** ********* steady **** *** **** ******* *****, despite *** ****-***** ******** *****.

*********'* **************, ******* **** *** *********** complaints, ** ****** ** ********** ** exploits **** ** ****** *** *** foreseeable ******.

Compound ******* *** *********

*** ************ ** ********* ******* ** Moobot *********** *** ******** ** *********'* cybersecurity *****. ******* ** ******** *** remedy ***** ******** ******** ************* ****** it ***** ** *********, ******* ***** alleged**,*** *&* *********, *** ********.

************, ********* ******* ** ************ ****** users ** *** ******** ** *** vulnerability (*** ******* * ********** **** a *******), *** *** *** ** potentially ******** ** ******* ***** ******** to ****** ******.

Comments (31)
UI
Undisclosed Integrator #1
Dec 09, 2021

IPVM Image

*****, *** ****** **** **** ******** disappear ** ******** *** ** ******* they *****.

(11)
(7)
RS
Robert Shih
Dec 09, 2021
Independent

*'** ********* **** ** ** ***** to **** *** **** *** ******* at *** ******** ****** ** *****. Besides, ********* ** ******* ** ******** time ****** **** ** *** ***.

(3)
(1)
UD
Undisclosed Distributor #2
Dec 09, 2021

*******, ********* ** ******* ** ******** time ****** **** ** *** ***

*** ********* *** **** ** *** world ****.

(4)
(1)
DD
Damion Dick
Jan 24, 2022

*** ******** *** ****** ******** *** others ** *** ****. ****** ****** license **** *** *** **** ** a ****** ** *** *********** ****** you **** **** **** ** ****. That ** *** **** **** *** market ***** *** ** ********.**** ******* to ***** ************* *** ***** ***************, i ** **** ******* **** **** their ***** ** *************** ***.********... ** not ****** **** ******* ** *** internet. ** *** ** *** **** how, **** ******* *** ****.

(1)
(4)
(1)
Avatar
Blake Murphy
Jan 25, 2022

*** ***** *** ** **** "********* of *** *****".... ** ****, ****'* one ***!

(1)
(2)
Avatar
David Coles
Jan 25, 2022

** *** ******* **** ********* *** cyber ******** ****** ** **** *** fact **'* **** ** ** ********** by *****? ****** ******** **** *'* kind ** ***** ** *** *********. We *** ****** ** ****** **** in ***** ******'* *** ** ** it ** ******* ** * ********* mandate ******* ** *** ********* **** we ******'* **** *****? ** **'* about *** ********** *** ** ******* force ***** *** ******** ******* **** firmware/software ** ** **** *** **** "verified" **** *** ****** **** **** calling *** ** ******* ** *****? Could ** ******* ****?

(3)
UI
Undisclosed Integrator #9
Jan 25, 2022

*** ****** ****** ** *** ** both *********. *** **** **** ***** programmers ********** ********* ** ****** ** a ****** ******** ****** ** ****** malice, ** *********. **** **** ****.

****** *** ** ***** **** ********* is ***** ** ** ************ ** multiple ***** ******* ********* *** *** just ***** ** ** *** **** BS ***** **** *** ****** ***. Thus *** ***** *********.

UM
Undisclosed Manufacturer #3
Jan 23, 2022

*, *** ***, ************* * **** ************* ******** *** resulted ** * **** ************* *******.

(6)
UM
Undisclosed Manufacturer #4
Jan 24, 2022

* **** ***** **** * ***** national ********** **** *** ** ****** like **** *** ****** * ***** national *********, ** ** **** ********* to ***** ** **** ******* *** the **** ** **** ***** ****** arise. **** *** ********** ****-******** *******, similar ** *** **** ******** ******** operate, ***** **** ***** * ****** on * *** ******** (*****, ******, monthly), *** **** ******** *** ******* the ****** ** ***** ***, ******** that *** ******* *** ******* ******* having ** **** * ***** ** each ******** *** ****** **** ******* which ***** **** ******** *******. ** course, ***** ** *** *********** ** an ****** ***** ***** *** ****** down *** ******, ** *** ****** occurring ** ** *********** ****....

UM
Undisclosed Manufacturer #5
Jan 25, 2022

* ********** ******'* **** *********** **** equipment ******* **** ** *****....

DD
Damion Dick
Jan 25, 2022

***** *** **** *********** ** ******* home ** *** ***? ** ******? or ******? ** **? ** ***********? Are *** ********** ******* **** ***** manufacturers ****'* ******* **** ***** *********** to ******* ****** ******, **** ******.

(1)
UE
Undisclosed End User #8
Jan 25, 2022

***** *** *********/***** *** ***** **** can ****** *********, ******** *** ************ on * ********** *****. **** *** not *** ******** **** ******* ****** counts *** **** *** **** ** manage **+ ******* **** ** ******* they *** * ******** **** *** a ******** *****.

****/***** ********* = $$$.

(1)
UM
Undisclosed Manufacturer #6
Jan 25, 2022
IPVMU Certified

*'* *** ****** ** ****** *********, but *** *** **** ** ******** the ******* ****** ******* **** ******* that ********* *********** ********* *** ***** and ******** * ***** *** **** day. *** ** ******* **** *** other ********* ***** ** **** ** do *** ****? **** ***** ******** argue **** *** ***** ********* ***'* have ***** ************* ******, *** * think **'* **** *** **** **** their ****** *****'* **** ********** ***...

**** ********* ******:

"********* ** * *** *** *** quickly ******** *** *** ******,***-****-******** ******** * ***** *** *** vulnerability ** *** **** *** ** the ****** **********’* **********."

(1)
(1)
(2)
(1)
JH
John Honovich
Jan 25, 2022
IPVM

**** ******* **** ********* *********** ********* the ***** *** ******** * ***** the **** ***

**** ** ********* *****. ** **** Hikvision ****** * ****** ** ******* a ***,**** *** **********'* ******************* *** *** *****:

IPVM Image

**'* ********** **** ******** *** ** publicly ****** **** *************** **** *** it ***** ****** *** ** ******* the ************* *** *** ***** **** it ******** *** ****** ** ** at *** *** ** *** ****** -********* *** "******* ***** ** ******** Vulnerability," ********* ***+ ******* *******

(2)
UM
Undisclosed Manufacturer #6
Jan 25, 2022
IPVMU Certified

***** * *******'* **** **** ** own ***** ** * ********, *** the **** * ******** ** (*****) was ****** **** ********* ****.

"********* ** * *** *** *** quickly ******** *** *** ******,***-****-******** ******** * ***** *** *** vulnerability ** *** **** *** ** the ****** **********’* **********."

** ** **** ********* * ****** to ******* *** *** (** *** timeline *****), ******'* ** ** **** to ***** ** *** ******* **** the ******** ******* ** *** ******** report *********** *****(***** ***'** **** ****** ** ** in **** *******?).

* ***'* ******* **** **** ***** report ****** ** ** ** ******* (maybe * ******), ** * ******* appreciate ** ******** ***** ******* ** the **** *******.

UI
Undisclosed Integrator #1
Jan 25, 2022

********'* ****** ** *** ********* *****. When ** **** "**** *** ** the ****** **********'* **********", ** ***** the *** *********** **** ******. **** was *** *** *** ******* **** released. *******, ** **** *****, *********** had ********** **** **** ******* ****** before.

(3)
JH
John Honovich
Jan 25, 2022
IPVM

*** ****:

********* *********** ********* *** ***** *** released * ***** *** **** ***.

******** ****:

******** * ***** *** *** ************* on *** **** *** ** *** threat **********’* **********

**** ******** **** ** *** "********* false", **** ******** *** ***** *** same *** ** *** ********** ********* but ********* *** *** ** ** "immediately" ** *** *******.

** ***'* ******* ***** ****** ** the ****** *** **'** ***** ** clarify ****** **** *********** ***** ********* or ********.

(1)
UM
Undisclosed Manufacturer #6
Jan 25, 2022
IPVMU Certified

******, *** ********** *************/**** *** **** useful.

UI
Undisclosed Integrator #1
Jan 25, 2022

********* *********** ********* *** ***** *** released * ***** *** **** ***. Are ** ******* **** *** ***** companies ***** ** **** ** ** the ****?

** ** *****, **** *** ************ **********(**************'* ********). *** ************* *** ******** ** them ** **** **, *** *********** waited ***** ********* *** *** ***** to ** ****** *** ******** ****** they **** ********* *** ******* ** September **. **** ** * ****** common *** ** **** **** ***************. For *******, ** *******, **** *** Nozomi ********** ****** ***************, *** **** *** ******* **** working ** *** *** *** **** time - ********-** ******** *** ******** ** ******, **** ****** *** ************.

************** ****** ************ ******* *** ******* **** ** 3 ******, ***** *** **** ***** of ******** ********. *** ** *** can ***, **** ** *** * case ** ********* ******** *** * patch *** ** *** ***. *** even *****.

**** ***** ******** ***** **** *** other ********* ***'* **** ***** ************* issues, *** * ***** **'* **** the **** **** ***** ****** *****'* been ********** ***

*** ****'********** ** ***** ************ ************* *************** and ********. ***** ********* ** **** ***************. Do **** **** ******** ***************? * will ***** *** **** *** ***'* see ******* ** **** ** ***** or ******** ******* (** *** ** I've ****, ****** - ** ******** has, **** ****** ****** ****). **** of **** ** ******* ********* ******* are **** ******* ****, ****, "*************" who ****** **** **********. *** ******* part ** **** **** ***** ** have ****** ******** *********, **** ******** ** **** *** *********** ** audit ***** ****.

** *** ** ****** *** ****** world, *** **** **** *********** ** ********-***** *******, *** *******, and ******. * ***** ***** **** ***** devices *** *** **** ****** ** botnets, ******* **** *** *) ******, 2) ******* ** *** ********, *) made *******, *** *) ********** ** non-professionals. *** ******** ***'* **** **** Cisco ******* ** ******* [******** ******], even ****** ****'** *** ***************. **'* probably * ******* ********* **** *********.

* ***'* ***** ********* *** ***** popular, ** *** ***** **** ** poorly ******* **********/**************, *** * ** think **** **** **** * ************** to ***** ****** ********. **** ****** also ***** ****** ******** ** **********. And **** ****** ********** ****** **** OEMs, ** **** *** **** *** are **** ********** **** ****'* ********* Hikua ***'* ************* ***** ********* *******.

(2)
UI
Undisclosed Integrator #7
Jan 25, 2022

***'* *** *** *** ***** **** beating * **** *****. ****'* **** point **** **** ****. ** ***** there ** ****** * ***** ** make ** ***** *** *****. ****** stated *** **** ** ********** ******* Hikvision, *** **** ******* ** *** complete ***** *** **. ** ** to *** ***** **** *** *** becoming **** ********. * **** **** I **** ** ******** **** * read **** ******* ***** ***** ** be ********* ******** *** **** ******** and *************. *******...***, **** *** *** following **** **** ** *** *** are ***** ***** ****. **** ***** other ********* ******** ****** *** ** China? *** **** ** *** ***** an ******?

(1)
(3)
(1)
JH
John Honovich
Jan 25, 2022
IPVM

#*, ****** *** **** ***** *******!

** ***** ***** ** ****** * slant ** **** ** ***** *** worse

*** *** *********? ******* *** ****** bad *** *************** **** **** ******** root ****** (**** *********'* ****) *** pretty ***.

*** **** ** *** ***** ** iphone?

***, * ** *** *** ******* ********** * '*** **** ** PRC *****' ******.

UI
Undisclosed Integrator #7
Jan 25, 2022

*** *** *******, ** ** * serious *************. ** *** *** **** aware. *** *************** *** ******* **** all ******** *** *** *************. * believe *** ****** ** ***** ** I **** ***** ** ** ****.

JH
John Honovich
Jan 25, 2022
IPVM

*** *************** *** ******* **** *** products *** *** *************

**, **** *************** *** *** **** serious **** ******, *.*.,**** ********* *** ****** * *.* out ** **, ***** ** * ****-******** ******* system (****).

(1)
UI
Undisclosed Integrator #7
Jan 25, 2022

***, **** ** **** *******. *** are ********** *******. *** **** ** this ** *** ****, *** *** are ***** ******* *** ***** ** we ****** ***** ** ********.

JH
John Honovich
Jan 25, 2022
IPVM

**** ** **** ** *** ****

**** *** ***** ******** **** ***** and ** ***** ** ******* *****. If ****'* *** **** ** ***, we *** ***** ** ********.

(1)
(1)
UM
Undisclosed Manufacturer #6
Jan 26, 2022
IPVMU Certified

* **** ***** *** ****** *** point ****. **** ***********#*'* ******* ******** again: "

"***'* *** *** *** ***** **** beating * **** *****."

**'* *** ***** *** ******** ******* or ********** ************* ****** ** *******, it's ****** *** *********, *** ********, and **** ******* "*******".

***'* *** ** *****, * ********** that **** *** ********* ************* ******, discovering *** *******, ********* *********** *** so **, *** ** **** ***** a *** **** ** *****. **'* like ***** **** *** ******** ********* new, **'* ***** ****. ***** ***** of *********** ***** **** **** ** your ******** ****.

** *** ** (*** **** **** for * *****), ***** *** ************* issues (*** ****) **** ********* *** Dahua. **** *** *** **** ******** workers/writers, **** **** **** *** *** enthusiasm ***'* ****** ** **** *****-*****.

(3)
JH
John Honovich
Jan 26, 2022
IPVM

**** ***********#*'* ******* ******** *****: " "Don't *** *** *** ***** **** beating * **** *****."

*** *** **** ** **** **** as * **** ***** *** *** US ********** ** ** *** ***** of ******** ** ************* *** ** these *********, ** **'* * **** live ****** ***** *** ** ** of ******** ******** ** * *********** portion ** *** ********. ******* ******* are ********* ********** *** *****, *.*.,******* **** *****.

** **** ***** * *** **** at *****.

****** *** ***** ** **** ******* interest ****** ** ****** *** *********** covers. ***** ** *** *** * consulting **** ******** ** ******** ***********' interests, ** ** ******** **** **** will **** *** ******** *** **** relevant ** *********** **** ******. ** strive *** ******** ** ***** ** cover, ** ****** **** ********'* *********.

**** ****, ******* ** **** ** two ** **** ** ****** *****? I ***'* *** ** **** ********** do ** *** ** ***** *** good ***** **** *********** *** **** cover ***** ******.

(1)
UM
Undisclosed Manufacturer #6
Jan 26, 2022
IPVMU Certified

***** ********** **** *** ***'* ***** for ***. ******* *** *** ****** IPVM ****, *** ***** ******* ** in *** ***** ** ***** ** number ** ********. ** ********** ***** that **'* ** ********* *****, *** maybe ** **** ***** **** "* bit *** **** ** *****" ***'* necessarily *** ***?*'** ** **** ******, it's *** ******, ***** *** ********* trolling ******** ** *********** ***** ******** fills ** ***.

************, *'* **** ** *** * Cybersecurity ******* (******** **** **** **** China), ******* ** **-***** ******/***** ** a ******** *** (** ********), *********** on ********/****** ************** *** *******/**** ***.

UM
Undisclosed Manufacturer #4
Jan 25, 2022

** ********* ******, ** ***'* ***** a ******* **** *****. ** ** about ******** **** **** **** * company **** *** ********** *******, ** well ** * ****** **** ***** record ** ***** ********, *** **** quality ** *******.

** ***** ***** ******* ************* ******** by * ******* ********** ** ***** government, ** ***** ** ******* *********. There **** **** ******** ***** ******** from ***** **********-********** *********, ********** **** it ******** ****-***** ** ******** ******** / *******, *** ******** ** *** is *********** ******...

(1)
UD
Undisclosed Distributor #2
Jan 25, 2022

*** **** ** ********** ******* *********, and **** ******* ** *** ******** until *** **

***, * ***** **, * ********** would **** ** ** **** ** destroy ********* & *******. **** *** the * *********, ** *** ****** of ** ****, **** * **** the ****. **** *** ***** ********* scum *** * ******* *** ***** controlled ** *** *** & *** being **** ** **** ** ***** quest *** ***** **********.

*** ***** ****** ** ***** ****** with ***** ******** (*** ******** ****** a ***** % ** ***** ******* line) ****** **** ****** **** **** a ***** **** **** **** ** bad **** & ****** ** *******.

(1)
(1)
UM
Undisclosed Manufacturer #6
Jan 26, 2022
IPVMU Certified

*'* *** ***% **** **** **** isn't *********, *** *'** ****** ** believe *** **** ***** ****. ***'** entitled ** **** **** *** ******* of ****** *** ** ***** **** harsh ******** *** ****** ********** ** you *** ******* - * ***** quickly ******* **** **** ** ******** and * **** *** ******* **** frustration ***. * ***** ********** **** my **** ***** **** ** ****** fuel ** *** ****, *** **** all *** ******* ***'* ** ****** (and *****) ** * **** ************ manner?

** *** *** **** ******* *********** I ***** **** ******** *** *** Agree ****** ******* ** *** ********* button.