InfectedSlurs is a threat actor name linked in reporting to a campaign expanding the Mirai botnet. The activity involved exploitation of OS command injection flaws in end-of-life GeoVision IoT devices, specifically CVE-2024-6047 and CVE-2024-11120, abusing the /DateSetting.cgi endpoint via the szSrvIpAddr parameter to download and execute an ARM Mirai variant dubbed LZRD. Reporting also stated that additional exploited vulnerabilities included older bugs in Hadoop YARN, CVE-2018-10561, and DigiEver systems. The content directly identifies the campaign as appearing linked to a group known as InfectedSlurs. No further attribution, targeting profile, sub-groups, or nation-state affiliation is provided in the available content. Known alias in the provided content: infectedslurs.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Akamai observed attacks in April targeting GeoVision devices through two OS command injection flaws - CVE-2024-6047 and CVE-2024-11120 - to download and run an ARM variant of Mirai dubbed LZRD.
Akamai observed attacks in April targeting GeoVision devices through two OS command injection flaws - CVE-2024-6047 and CVE-2024-11120 - to download and run an ARM variant of Mirai dubbed LZRD.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.