[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/mirai-variant-targets-iot-exploits/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/ "Trend Reports")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 11 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![IoT Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)IoT Security](https://unit42.paloaltonetworks.com/product-category/iot-security/ "IoT Security")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Chao Lei](https://unit42.paloaltonetworks.com/author/chao-lei/)
  * [Zhibin Zhang](https://unit42.paloaltonetworks.com/author/zhibin-zhang/)
  * [Yiheng An](https://unit42.paloaltonetworks.com/author/yiheng-an/)
  * [Cecilia Hu](https://unit42.paloaltonetworks.com/author/cecilia-hu/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 22, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/)
  * [CVE-2019-12725](https://unit42.paloaltonetworks.com/tag/cve-2019-12725/)
  * [CVE-2019-17621](https://unit42.paloaltonetworks.com/tag/cve-2019-17621/)
  * [CVE-2019-20500](https://unit42.paloaltonetworks.com/tag/cve-2019-20500/)
  * [CVE-2021-25296](https://unit42.paloaltonetworks.com/tag/cve-2021-25296/)
  * [CVE-2021-46422](https://unit42.paloaltonetworks.com/tag/cve-2021-46422/)
  * [CVE-2022-27002](https://unit42.paloaltonetworks.com/tag/cve-2022-27002/)
  * [CVE-2022-29303](https://unit42.paloaltonetworks.com/tag/cve-2022-29303/)
  * [CVE-2022-30023](https://unit42.paloaltonetworks.com/tag/cve-2022-30023/)
  * [CVE-2022-30525](https://unit42.paloaltonetworks.com/tag/cve-2022-30525/)
  * [CVE-2022-31499](https://unit42.paloaltonetworks.com/tag/cve-2022-31499/)
  * [CVE-2022-36266](https://unit42.paloaltonetworks.com/tag/cve-2022-36266/)
  * [CVE-2022-40005](https://unit42.paloaltonetworks.com/tag/cve-2022-40005/)
  * [CVE-2022-45699](https://unit42.paloaltonetworks.com/tag/cve-2022-45699/)
  * [CVE-2023-1389](https://unit42.paloaltonetworks.com/tag/cve-2023-1389/)
  * [CVE-2023-25280](https://unit42.paloaltonetworks.com/tag/cve-2023-25280/)
  * [CVE-2023-27240](https://unit42.paloaltonetworks.com/tag/cve-2023-27240/)
  * [IoT](https://unit42.paloaltonetworks.com/tag/iot/)
  * [IoT Security](https://unit42.paloaltonetworks.com/tag/iot-security/)
  * [Mirai](https://unit42.paloaltonetworks.com/tag/mirai/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/?pdf=download&lg=en&_wpnonce=7052973960 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/?pdf=print&lg=en&_wpnonce=7052973960 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=IoT%20Under%20Siege:%20The%20Anatomy%20of%20the%20Latest%20Mirai%20Campaign%20Leveraging%20Multiple%20IoT%20Exploits&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-targets-iot-exploits%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-targets-iot-exploits%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-targets-iot-exploits%2F&title=IoT%20Under%20Siege:%20The%20Anatomy%20of%20the%20Latest%20Mirai%20Campaign%20Leveraging%20Multiple%20IoT%20Exploits "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-targets-iot-exploits%2F&text=IoT%20Under%20Siege:%20The%20Anatomy%20of%20the%20Latest%20Mirai%20Campaign%20Leveraging%20Multiple%20IoT%20Exploits "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-targets-iot-exploits%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=IoT%20Under%20Siege:%20The%20Anatomy%20of%20the%20Latest%20Mirai%20Campaign%20Leveraging%20Multiple%20IoT%20Exploits%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-targets-iot-exploits%2F "Share in Mastodon")

## Executive Summary

Since March 2023, Unit 42 researchers have observed threat actors leveraging several IoT vulnerabilities to spread a variant of the Mirai botnet. The vulnerabilities exploited include those listed in the following table:

|-----------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------|
| **CVE/Product**                                                                                                                                     | **Description**                                                   |
| [CVE-2019-12725](https://nvd.nist.gov/vuln/detail/CVE-2019-12725)                                                                                   | Zeroshell Remote Command Execution Vulnerability                  |
| [CVE-2019-17621](https://nvd.nist.gov/vuln/detail/CVE-2019-17621)                                                                                   | D-Link DIR-859 Remote Command Injection Vulnerability             |
| [CVE-2019-20500](https://nvd.nist.gov/vuln/detail/CVE-2019-20500)                                                                                   | D-Link DWL-2600AP Remote Command Execution Vulnerability          |
| [CVE-2021-25296](https://nvd.nist.gov/vuln/detail/CVE-2021-25296)                                                                                   | Nagios XI Remote Command Injection Vulnerability                  |
| [CVE-2021-46422](https://nvd.nist.gov/vuln/detail/CVE-2021-46422)                                                                                   | Telesquare SDT-CW3B1 Router Command Injection Vulnerability       |
| [CVE-2022-27002](https://nvd.nist.gov/vuln/detail/CVE-2022-27002)                                                                                   | Arris TR3300 Remote Command Injection Vulnerability               |
| [CVE-2022-29303](https://nvd.nist.gov/vuln/detail/CVE-2022-29303)                                                                                   | SolarView Compact Command Injection Vulnerability                 |
| [CVE-2022-30023](https://nvd.nist.gov/vuln/detail/CVE-2022-30023)                                                                                   | Tenda HG9 Router Command Injection Vulnerability                  |
| [CVE-2022-30525](https://nvd.nist.gov/vuln/detail/CVE-2022-30525)                                                                                   | Zyxel Command Injection Vulnerability                             |
| [CVE-2022-31499](https://nvd.nist.gov/vuln/detail/CVE-2022-31499)                                                                                   | Nortek Linear eMerge Command Injection Vulnerability              |
| [CVE-2022-37061](https://nvd.nist.gov/vuln/detail/CVE-2022-37061)                                                                                   | FLIR AX8 Unauthenticated OS Command Injection Vulnerability       |
| [CVE-2022-40005](https://nvd.nist.gov/vuln/detail/CVE-2022-40005)                                                                                   | Intelbras WiFiber 120 AC inMesh Command Injection Vulnerability   |
| [CVE-2022-45699](https://nvd.nist.gov/vuln/detail/CVE-2022-45699)                                                                                   | APsystems ECU-R Remote Command Execution Vulnerability            |
| [CVE-2023-1389](https://nvd.nist.gov/vuln/detail/CVE-2023-1389)                                                                                     | TP-Link Archer Router Command Injection Vulnerability             |
| [CVE-2023-25280](https://nvd.nist.gov/vuln/detail/CVE-2023-25280)                                                                                   | D-link DIR820LA1\_FW105B03 Command injection vulnerability         |
| [CVE-2023-27240](https://nvd.nist.gov/vuln/detail/CVE-2023-27240)                                                                                   | Tenda AX3 Command Injection Vulnerability                         |
| [CCTV/DVR](https://www.kerneronsec.com/2016/02/remote-code-execution-in-cctv-dvrs-of.html)                                                          | CCTV/DVR Remote Code Execution                                    |
| [EnGenius EnShare](https://www.exploit-db.com/exploits/42114)                                                                                       | EnGenius EnShare Remote Code Execution Vulnerability              |
| [MVPower DVR](https://www.rapid7.com/db/modules/exploit/linux/http/mvpower_dvr_shell_exec)                                                          | MVPower DVR Shell Unauthenticated Command Execution Vulnerability |
| [Netgear DGN1000](https://seclists.org/bugtraq/2013/Jun/8)                                                                                          | Netgear DGN1000 Remote Code Execution Vulnerability               |
| [Vacron NVR](https://ssd-disclosure.com/ssd-advisory-vacron-nvr-remote-command-execution/)                                                          | Vacron NVR Remote Code Execution Vulnerability                    |
| [MediaTek WiMAX](https://www.f5.com/labs/articles/threat-intelligence/brickerbot-do-good-intentions-justify-the-meansor-deliver-meaningful-results) | MediaTek WiMAX Remote Code Execution                              |

The threat actors have the ability to gain complete control over the compromised devices, integrating those devices into the botnet. These devices are then used to execute additional attacks, including distributed denial-of-service (DDoS) attacks.

Palo Alto Networks [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) customers receive protection through [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions) such as [Internet of Things (IoT) Security](https://www.paloaltonetworks.com/network-security/smart-devices-smarter-iot-security?utm_source=google-jg-amer-cdss&utm_medium=paid_search&utm_term=palo%20alto%20networks%20iot%20security&utm_campaign=google-cdss-iot_security-amer-ca-awareness-en&utm_content=gs-19633824690-151442986731-646705931499&sfdcid=7014u000001hHCRAA2&gclid=EAIaIQobChMI1Lm26OmS_QIVQUNyCh1G3gKWEAAYASAAEgJ3KvD_BwE), [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention), [WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire) and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering), which can help detect and block the exploit traffic and malware.

| **Related Unit 42 Topics** | [**IoT**](https://unit42.paloaltonetworks.com/tag/IoT/), **[Mirai](https://unit42.paloaltonetworks.com/tag/mirai/), [botnet](https://unit42.paloaltonetworks.com/tag/botnet)** |
|----------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Campaign Analysis

On March 14, 2023, Unit 42 researchers observed some remote command execution exploit traffic from our internal threat-hunting system, originating from 185.44.81\[.\]114. The threat actor tried to download a shell script downloader as a file named y from hxxp://zvub\[.\]us/.

If executed, the shell script downloader would download and execute the following bot clients to accommodate different Linux architectures:

* hxxp://185.225.74\[.\]251/armv4l
* hxxp://185.225.74\[.\]251/armv5l
* hxxp://185.225.74\[.\]251/armv6l
* hxxp://185.225.74\[.\]251/armv7l
* hxxp://185.225.74\[.\]251/mips
* hxxp://185.225.74\[.\]251/mipsel
* hxxp://185.225.74\[.\]251/sh4
* hxxp://185.225.74\[.\]251/x86\_64
* hxxp://185.225.74\[.\]251/i686
* hxxp://185.225.74\[.\]251/i586
* hxxp://185.225.74\[.\]251/arc
* hxxp://185.225.74\[.\]251/m68k
* hxxp://185.225.74\[.\]251/sparc

After executing the bot client, the shell script downloader will delete the client executable file to cover its tracks.

Unit 42 researchers conducted an analysis of the malware host domain and found out there are two IP addresses corresponding to the domain zvub\[.\]us:

* 185\.44.81\[.\]114 (From Aug. 15, 2022, to March 24, 2023)
* 185\.225.74\[.\]251 (After March 25, 2023)

Upon conducting a thorough retrospective analysis, we noticed telnet brute force attempts from 185.44.81\[.\]114 since Oct. 6, 2022, and attempts to exploit multiple vulnerabilities since March 14, 2023.

Unit 42 researchers also noticed another campaign from source IP 193.32.162\[.\]189 since April 11, 2023, that delivers the same shell downloader from zvub\[.\]us, as shown in Figure 1. Based on our analysis, we believe that the same threat actor operated these two campaigns for the following reasons:

* The two campaigns share the same infrastructure.
* The botnet samples are almost identical.

![Image 1 is a chart of the vulnerability, exploit attempts from October 2022 to May 2023. The highest count is in April the highest counts are in April, 2023, with 821, and then in May 2023 with 924.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/chart-3.png) Figure 1. Vulnerability exploit attempts.

Figure 2 is a diagram illustrating the campaign overview.
![Image 2 is a timeline of the campaign overview. It starts with the attack source, IP, and lists all of the exploits, including new exploits. It starts mid August, 2022, and flows through May 1, 2023.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-2-1.png) Figure 2. Campaign overview diagram.

## Malware Analysis

Based on behavior and patterns Unit 42 researchers observed while analyzing the downloaded botnet client samples, we believe the sample is a variant of the Mirai botnet.

Upon execution, the botnet client prints listening tun0 to the console. The malware also contains a function that ensures only one instance of this malware runs on the same device. If a botnet process already exists, the botnet client will terminate the current running process and start a new one.

For the botnet client configuration string, the Mirai variant (like [IZ1H9](https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/) and [V3G4](https://unit42.paloaltonetworks.com/mirai-variant-v3g4/)) will first initialize an encrypted string table and then retrieve the strings through an index. However, this Mirai variant will directly access the encrypted strings in the .rodata section via an index (as shown in Figure 3).
![Image 3 is a screenshot of the Mirai fairy and retrieving configurations strings. This is highlighted within a red box.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-3-1.png) Figure 3. Mirai variant retrieving configuration strings.

Also, notice that for Mirai variants like [IZ1H9](https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/) and [V3G4](https://unit42.paloaltonetworks.com/mirai-variant-v3g4/), the configuration contains a string that indicates the branch name of this variant (for example, /bin/busybox IZ1H9) while this variant does not have a branch name.

For the configuration decryption, this Mirai variant first uses a table key 0xDEADBEEF to generate a single-byte config decryption key 0x22, then for the encrypted configuration, the malware performs XOR decryption with the following bytewise operations:

encrypted\_char ^ 0x22 = decrypted\_char

During the analysis, Unit 42 researchers noticed that this Mirai sample doesn't contain the functionality to brute force telnet/SSH login credentials and exploit vulnerabilities, which means the only channels for spreading this variant are the botnet operator's manual vulnerability exploitation attempts.

## Conclusion

The widespread adoption of IoT devices has become a ubiquitous trend. However, the persistent security concerns surrounding these devices cannot be ignored. The Mirai botnet, discovered back in 2016, is still active today. A significant part of the reason for its popularity among threat actors lies in the security flaws of IoT devices.

These remote code execution vulnerabilities targeting IoT devices exhibit a combination of low complexity and high impact, making them an irresistible target for threat actors. As a result, protecting IoT devices against such threats becomes an urgent task.

To combat this threat, it is highly recommended that patches and updates are applied when possible.

Palo Alto Networks customers receive protection against vulnerabilities and malware through the following products and services:

* Next-Generation Firewall with a Threat Prevention security subscription can block the attacks with Best Practices via Threat Prevention signatures [30760](https://threatvault.paloaltonetworks.com/?query=30760), [37073](https://threatvault.paloaltonetworks.com/?query=37073), [37752](https://threatvault.paloaltonetworks.com/?query=37752), [54659](https://threatvault.paloaltonetworks.com/?query=54659), [54553](https://threatvault.paloaltonetworks.com/?query=54553), [54537](https://threatvault.paloaltonetworks.com/?query=54537), [54619](https://threatvault.paloaltonetworks.com/?query=54619), [58706](https://threatvault.paloaltonetworks.com/?query=58706), [57437](https://threatvault.paloaltonetworks.com/?query=57437), [55795](https://threatvault.paloaltonetworks.com/?query=55795), [57191](https://threatvault.paloaltonetworks.com/?query=57191), [90873](https://threatvault.paloaltonetworks.com/?query=90873), [92611](https://threatvault.paloaltonetworks.com/?query=92611), [93863](https://threatvault.paloaltonetworks.com/?query=93863), [92626](https://threatvault.paloaltonetworks.com/?query=92626), [92714](https://threatvault.paloaltonetworks.com/?query=92714), [93859](https://threatvault.paloaltonetworks.com/?query=93859), [92579](https://threatvault.paloaltonetworks.com/?query=92579), [93044](https://threatvault.paloaltonetworks.com/?query=93044), [93283](https://threatvault.paloaltonetworks.com/?query=93283), [93587](https://threatvault.paloaltonetworks.com/?query=93587), [93872](https://threatvault.paloaltonetworks.com/?query=93872), [93749](https://threatvault.paloaltonetworks.com/?query=93749), [93874](https://threatvault.paloaltonetworks.com/?query=93874), [93973](https://threatvault.paloaltonetworks.com/?query=93973).
* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention) has an inbuilt machine learning-based security detection that can detect exploit traffic in real time.
* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) can stop the malware with static signature detections.
* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [DNS Security](https://www.paloaltonetworks.com/network-security/dns-security) are able to block the C2 domain malware-hosting URLs.
* The Palo Alto Networks IoT security platform can leverage network traffic information to identify the vendor, model and firmware version of a device and identify specific devices that are vulnerable to the aforementioned CVEs.
* In addition, [IoT Security](https://www.paloaltonetworks.com/network-security/iot-security) has an inbuilt machine learning-based anomaly detection that can alert the customer if a device exhibits nontypical behavior, such as the following:
  * The sudden appearance of traffic from a new source
  * An unusually high number of connections
  * An inexplicable surge of certain attributes typically appearing in IoT application payloads

Palo Alto Networks has shared our findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org/).

## Indicators of Compromise

### Shell Script Downloader Samples

* 888f4a852642ce70197f77e213456ea2b3cfca4a592b94647827ca45adf2a5b8

### Mirai Samples

* b43a8a56c10ba17ddd6fa9a8ce10ab264c6495b82a38620e9d54d66ec8677b0c
* b45142a2d59d16991a38ea0a112078a6ce42c9e2ee28a74fb2ce7e1edf15dce3
* 366ddbaa36791cdb99cf7104b0914a258f0c373a94f6cf869f946c7799d5e2c6
* 413e977ae7d359e2ea7fe32db73fa007ee97ee1e9e3c3f0b4163b100b3ec87c2
* 2d0c8ab6c71743af8667c7318a6d8e16c144ace8df59a681a0a7d48affc05599
* 4cb8c90d1e1b2d725c2c1366700f11584f5697c9ef50d79e00f7dd2008e989a0
* 461f59a84ccb4805c4bbd37093df6e8791cdf1151b2746c46678dfe9f89ac79d
* aed078d3e65b5ff4dd4067ae30da5f3a96c87ec23ec5be44fc85b543c179b777
* 0d404a27c2f511ea7f4adb8aa150f787b2b1ff36c1b67923d6d1c90179033915
* eca42235a41dbd60615d91d564c91933b9903af2ef3f8356ec4cfff2880a2f19
* 3f427eda4d4e18fb192d585fca1490389a1b5f796f88e7ebf3eceec51018ef4d
* aaf446e4e7bfc05a33c8d9e5acf56b1c7e95f2d919b98151ff2db327c333f089
* 4f53eb7fbfa5b68cad3a0850b570cbbcb2d4864e62b5bf0492b54bde2bdbe44b

### Infrastructure

* zvub\[.\]us
* 185\.225.74\[.\]251
* 185\.44.81\[.\]114
* 193\.32.162\[.\]189

## Additional Resources

* [TP-Link WAN-SIDE Vulnerability CVE-2023-1389 Added to the Mirai Botnet Arsenal](https://www.zerodayinitiative.com/blog/2023/4/21/tp-link-wan-side-vulnerability-cve-2023-1389-added-to-the-mirai-botnet-arsenal) - Zero Day Initiative
* [Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet Campaigns](https://unit42.paloaltonetworks.com/unit42-finds-new-mirai-gafgyt-iotlinux-botnet-campaigns/) - Unit 42, Palo Alto Networks
* [Multi-exploit IoT/Linux Botnets Mirai and Gafgyt Target Apache Struts, SonicWall](https://unit42.paloaltonetworks.com/unit42-multi-exploit-iotlinux-botnets-mirai-gafgyt-target-apache-struts-sonicwall/) - Unit 42, Palo Alto Networks
* [Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices](https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/) - Unit 42, Palo Alto Networks
* [Mirai Variant V3G4 Targets IoT Devices](https://unit42.paloaltonetworks.com/mirai-variant-v3g4/) - Unit 42, Palo Alto Networks

## Appendix

Campaign-related vulnerability information is listed below:

[**CVE-2019-12725**](https://nvd.nist.gov/vuln/detail/CVE-2019-12725)**: Zeroshell Remote Command Execution Vulnerability**

This malicious traffic was first detected as a part of the campaign on March 14, 2023. The command execution vulnerability is due to the failure to sanitize the value of x509type in the kerbynet component of Zeroshell
![Image 4 is a screenshot of the Zeroshell remote command execution vulnerability. The name of the host is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-4-1.png) Figure 4. CVE-2019-12725 exploit in the wild.

[**CVE-2019-17621**](https://nvd.nist.gov/vuln/detail/CVE-2019-17621)**: D-Link DIR-859 Remote Command Injection Vulnerability**

We captured this exploit traffic on May 1, 2023. The exploit targets a command injection vulnerability in the D-Link wireless router's /gena.cgi component, which does not successfully sanitize the user input in the service parameter. This leads to arbitrary command execution.
![Image 5 is a screenshot of the D-Link DIR-859 remote command injection vulnerability. The host has been redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-5-1.png) Figure 5. CVE-2019-17621 exploit in the wild.

[**CVE-2019-20500**](https://nvd.nist.gov/vuln/detail/CVE-2019-20500)**: D-Link DWL-2600AP Remote Command Execution Vulnerability**

The exploit was detected on April 11, 2023. The exploit works due to the D-Link wireless router admin.cgi component failing to adequately sanitize the user-supplied input data, which leads to remote command execution.
![Image 6 is a screenshot of the D-Link DWL-2600AP remote command execution vulnerability. The host has been redacted. This exploit allows for remote command execution.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-6-1.png) Figure 6. CVE-2019-20500 exploit in the wild.

[**CVE-2021-25296**](https://nvd.nist.gov/vuln/detail/CVE-2021-25296)**: Nagios XI Remote Command Injection Vulnerability**

We observed this exploit traffic on April 11, 2023. The exploit targets the Nagios XI device's /nagiosxi/config/monitoringwizard.php component. If insufficient input validation is found, the attacker can exploit the vulnerability to launch a remote command injection attack.
![Image 7 is a screenshot of the Nagios XI remote command injection vulnerability. The host has been redacted. The screenshot is of the exploit traffic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-7-1.png) Figure 7. CVE-2021-25296 exploit in the wild.

[**CVE-2021-46422**](https://nvd.nist.gov/vuln/detail/CVE-2021-46422)**: Telesquare SDT-CW3B1 Router Command Injection Vulnerability**

The malicious traffic was first detected on March 14, 2023. The command injection vulnerability is due to the failure to sanitize the value of the cmd parameter in the cgi-bin/admin.cgi interface of the Telesquare router.
![Image 8 is a screenshot of the Telesquare SDT-CW3B1 router command injection vulnerability. It is a screenshot of the malicious traffic with the host redacted. The important portion is the command parameter in the CGI bin.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-8-1.png) Figure 8. CVE-2021-46422 exploit in the wild.

[**CVE-2022-27002**](https://nvd.nist.gov/vuln/detail/CVE-2022-27002)**: Arris TR3300 Remote Command Injection Vulnerability**

We captured this exploit traffic on April 14, 2023. The exploit targets a command injection vulnerability in the Arris TR3300's user.cgi component, which does not successfully sanitize the user input in the DDNS\_HOST parameter. This leads to a command injection.
![Image 9 is a screenshot of the exploit traffic of Arris TR3300 remote command injection vulnerability. The host has been redacted. The affected portion is part is the user.cgi component.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-9-1.png) Figure 9. CVE-2022-27002 exploit in the wild.

[**CVE-2022-29303**](https://nvd.nist.gov/vuln/detail/CVE-2022-29303)**: SolarView Compact Command Injection Vulnerability**

This exploit was detected on March 15, 2023. The exploit works due to the SolarView Compact confi\_mail.php component failing to adequately sanitize the user-supplied input data, which leads to command injection.
![Image 10 is a screenshot of the SolarView compact command injection vulnerability. The host, origin, and referrer have all been redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-10-1.png) Figure 10. CVE-2022-29303 exploit in the wild.

[**CVE-2022-30023**](https://nvd.nist.gov/vuln/detail/CVE-2022-30023)**: Tenda HG9 Router Command Injection Vulnerability**

We observed this exploit traffic on March 14, 2023. The exploit targets the Tenda HG9 router's /boaform/formPing component. If insufficient input validation is found, the attacker can exploit the vulnerability to launch a remote code execution attack
![Image 11 is a screenshot of the Tenda HG9 router command injection vulnerability. The host has been redacted. The screenshot is of the exploit traffic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-11-1.png) Figure 11. CVE-2022-30023 exploit in the wild.

[**CVE-2022-30525**](https://nvd.nist.gov/vuln/detail/CVE-2022-30525)**: Zyxel Command Injection Vulnerability**

This malicious traffic was first detected on March 14, 2023. The command injection vulnerability is due to the failure to sanitize the value of the mtu parameter in the /cgi-bin/handler interface of Zyxel.
![Image 12 is a screenshot of the Zyxel command injection vulnerability. The host is redacted. The affected portion is the mtg parameter in the CGI bin.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-12-1.png) Figure 12. CVE-2022-30525 exploit in the wild.

[**CVE-2022-31499**](https://nvd.nist.gov/vuln/detail/CVE-2022-31499)**: Nortek Linear eMerge Command Injection Vulnerability**

We captured this exploit traffic on May 1, 2023. The exploit targets a command injection vulnerability in the Nortek Linear eMerge device's card\_scan.php component, which does not successfully sanitize the user input in the ReaderNo parameter. This leads to remote command injection.
![Image 13 is a screenshot of the Nortek Linear eMerge command injection vulnerability. The host is redacted. The exploit affects the PHP code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-13-1.png) Figure 13. CVE-2022-31499 exploit in the wild.

[**CVE-2022-37061**](https://nvd.nist.gov/vuln/detail/cve-2022-37061)**: FLIR AX8 Unauthenticated OS Command Injection Vulnerability**

This exploit was detected on May 1, 2023. The exploit works due to the FLIR AX8 device's res.php component failing to adequately sanitize the user-supplied input data, which leads to OS command injection.
![Image 14 is a screenshot of the FLIR AX8 Unauthenticated OS command injection vulnerability. The host has been redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-14-1.png) Figure 14. CVE-2022-37061 exploit in the wild.

[**CVE-2022-40005**](https://nvd.nist.gov/vuln/detail/CVE-2022-40005)**: Intelbras WiFiber 120AC inMesh Command Injection Vulnerability**

We observed this exploit traffic on March 15, 2023. The exploit targets the Intelbras WiFiber device's /boaform/formPing6 component. If insufficient input validation is found, the attacker can exploit the vulnerability to launch a command injection attack.
![Image 15 is a screenshot of the Intelbras WiFiber 120AC inMesh command injection vulnerability. It is a screenshot of the exploit traffic with the host redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-15-1.png) Figure 15. CVE-2022-40005 exploit in the wild.

[**CVE-2022-45699**](https://nvd.nist.gov/vuln/detail/CVE-2022-45699)**: APsystems ECU-R Remote Command Execution Vulnerability**

This malicious traffic was first detected on April 12, 2023. The remote command execution vulnerability is due to a failure to sanitize the value of the timezone parameter in the /management/set\_timezone.
![Image 16 is a screenshot of the APsystems ECU-R remote command execution vulnerability. It is a screenshot of the malicious traffic with the host redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-16-1.png) Figure 16. CVE-2022-45699 exploit in the wild.

[**CVE-2023-1389**](https://nvd.nist.gov/vuln/detail/CVE-2023-1389)**: TP-Link Archer Router Command Injection Vulnerability**

We captured this exploit traffic on April 12, 2023. The exploit targets a command injection vulnerability in the TP-Link Archer router's cgi-bin/luci component, which does not successfully sanitize the user input in the country parameter. This leads to arbitrary command execution.
![Image 17 is a screenshot, with the host redacted, of the exploit traffic of the TP-Link Archer command injection vulnerability.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-17-1.png) Figure 17. CVE-2023-1389 exploit in the wild.

[**CVE-2023-25280**](https://nvd.nist.gov/vuln/detail/CVE-2023-25280)**: D-Link DIR820LA1\_FW105B03 Command injection vulnerability**

The exploit was detected on April 11, 2023. The exploit works due to the D-Link device /ping.ccp component failing to adequately sanitize the user-supplied input data, which leads to a command injection vulnerability.
![Image 18 as a screenshot of the D-Link DIR820LA1\_FW105B03 command injection vulnerability. Redacted in the screenshot is the host, the origin, and the referrer.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-18-1.png) Figure 18. CVE-2023-25280 exploit in the wild.

[**CVE-2023-27240**](https://nvd.nist.gov/vuln/detail/CVE-2023-27240)**: Tenda AX3 Command Injection Vulnerability**

We observed this exploit traffic on April 12, 2023. The exploit targets the Tenda AX3 router's /goform/AdvSetLanip component. If insufficient input validation is found, the attacker can exploit the vulnerability to launch a remote command injection attack.
![Image 19 is a screenshot of the Tenda AX3 command injection vulnerability. In the exploit traffic, the host has been redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-19-1.png) Figure 19. CVE-2023-27240 exploit in the wild.

[**CCTV/DVR Remote Code Execution**](https://community.broadcom.com/symantecenterprise/viewthread?MessageKey=098d8b01-0638-45cc-9261-99076b39d424&CommunityKey=dc76b213-82a9-4676-ac30-f50188193ccc&tab=digestviewer)

This exploit traffic was detected on March 14, 2023. The exploit targets a remote code execution in multiple CCTV/DVR devices' /language components. The component does not successfully sanitize the value of the HTTP parameter.
![Image 20 is a screenshot of the CCTV/DVR remote code execution. The exploit traffic has the host redacted. The exploit targets /language.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-20-1.png) Figure 20. CCTV/DVR exploit in the wild.

[**EnGenius EnShare Remote Code Execution Vulnerability**](https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=30364)

We detected this exploit traffic on April 12, 2023. The exploit works due to the /cgi-bin/usbinteract.cgi component of the EnGenius EnShare device failing to sanitize the value of the HTTP parameter path.
![Image 21 is a screenshot of EnGenius EnShare exploit traffic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-21-1.png) Figure 21. EnGenius Enshare exploit in the wild.

[**MVPower DVR Shell Unauthenticated Command Execution Vulnerability**](https://www.rapid7.com/db/modules/exploit/linux/http/mvpower_dvr_shell_exec/)

This malicious traffic was captured on April 11, 2023. The exploit works due to the MVPower DVR failing to sanitize user input, which in turn could lead to remote command execution.
![Image 22 is a screenshot of the MVPower DVR Shell unauthenticated command execution vulnerability. The host has been redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-22-1.png) Figure 22. MVPower DVR exploit in the wild.

[**Netgear DGN1000 Remote Code Execution Vulnerability**](https://seclists.org/bugtraq/2013/Jun/8)

We captured this exploit traffic on March 14, 2023. The exploit targets the setup.cgi component of Netgear DGN1000. The component does not sanitize the value of the HTTP parameter cmd, which leads to remote code execution.
![Image 23 is a screenshot of a Netgear DGN1000 exploit command code execution vulnerability. The host has been redacted in the screenshot.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-23-1.png) Figure 23. Netgear exploit in the wild.

[**Vacron NVR Remote Code Execution Vulnerability**](https://ssd-disclosure.com/ssd-advisory-vacron-nvr-remote-command-execution/)

We observed this exploit traffic on March 14, 2023. The exploit targets the Vacron NVR device's board.cgi component. If insufficient input validation is found, the attacker can exploit the vulnerability to launch a remote code execution attack.
![Image 24 is a screenshot of the Vacron NVR remote code execution, vulnerability. The host has been redacted in the screenshot.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-24-1.png) Figure 24. Vacron NVR exploit in the wild.

[**MediaTek WiMAX Remote Code Execution**](https://www.f5.com/labs/articles/threat-intelligence/brickerbot-do-good-intentions-justify-the-meansor-deliver-meaningful-results)

The exploit traffic was first detected as a part of a campaign on April 12, 2023. The remote code execution vulnerability is due to the failure to sanitize the value of the SYSLOGD\_REMOTE\_HOST parameter in the user.cgi interface of a MediaTek WiMAX device.
![Image 25 as a screenshot of the MediaTek WiMAX remote code execution.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128774-25-1.png) Figure 25. MediaTek WiMAX exploit in the wild.
Back to top

### Tags

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")
* [CVE-2019-12725](https://unit42.paloaltonetworks.com/tag/cve-2019-12725/ "CVE-2019-12725")
* [CVE-2019-17621](https://unit42.paloaltonetworks.com/tag/cve-2019-17621/ "CVE-2019-17621")
* [CVE-2019-20500](https://unit42.paloaltonetworks.com/tag/cve-2019-20500/ "CVE-2019-20500")
* [CVE-2021-25296](https://unit42.paloaltonetworks.com/tag/cve-2021-25296/ "CVE-2021-25296")
* [CVE-2021-46422](https://unit42.paloaltonetworks.com/tag/cve-2021-46422/ "CVE-2021-46422")
* [CVE-2022-27002](https://unit42.paloaltonetworks.com/tag/cve-2022-27002/ "CVE-2022-27002")
* [CVE-2022-29303](https://unit42.paloaltonetworks.com/tag/cve-2022-29303/ "CVE-2022-29303")
* [CVE-2022-30023](https://unit42.paloaltonetworks.com/tag/cve-2022-30023/ "CVE-2022-30023")
* [CVE-2022-30525](https://unit42.paloaltonetworks.com/tag/cve-2022-30525/ "CVE-2022-30525")
* [CVE-2022-31499](https://unit42.paloaltonetworks.com/tag/cve-2022-31499/ "CVE-2022-31499")
* [CVE-2022-36266](https://unit42.paloaltonetworks.com/tag/cve-2022-36266/ "CVE-2022-36266")
* [CVE-2022-40005](https://unit42.paloaltonetworks.com/tag/cve-2022-40005/ "CVE-2022-40005")
* [CVE-2022-45699](https://unit42.paloaltonetworks.com/tag/cve-2022-45699/ "CVE-2022-45699")
* [CVE-2023-1389](https://unit42.paloaltonetworks.com/tag/cve-2023-1389/ "CVE-2023-1389")
* [CVE-2023-25280](https://unit42.paloaltonetworks.com/tag/cve-2023-25280/ "CVE-2023-25280")
* [CVE-2023-27240](https://unit42.paloaltonetworks.com/tag/cve-2023-27240/ "CVE-2023-27240")
* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")
* [IoT Security](https://unit42.paloaltonetworks.com/tag/iot-security/ "IoT Security")
* [Mirai](https://unit42.paloaltonetworks.com/tag/mirai/ "Mirai")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/ "Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732")

### Table of Contents

* 

### Related Articles

* [A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "article - table of contents")
* [Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "article - table of contents")
* [Resurgence of the Prometei Botnet](https://unit42.paloaltonetworks.com/prometei-botnet-2025-activity/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
