InfectedSlurs
InfectedSlurs is a threat actor name linked in reporting to a campaign expanding the Mirai botnet. The activity involved exploitation of OS command injection flaws in end-of-life GeoVision IoT devices, specifically CVE-2024-6047 and CVE-2024-11120, abusing the /DateSetting.cgi endpoint via the szSrvIpAddr parameter to download and execute an ARM Mirai variant dubbed LZRD. Reporting also stated that additional exploited vulnerabilities included older bugs in Hadoop YARN, CVE-2018-10561, and DigiEver systems. The content directly identifies the campaign as appearing linked to a group known as InfectedSlurs. No further attribution, targeting profile, sub-groups, or nation-state affiliation is provided in the available content. Known alias in the provided content: infectedslurs.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Akamai observed attacks in April targeting GeoVision devices through two OS command injection flaws - CVE-2024-6047 and CVE-2024-11120 - to download and run an ARM variant of Mirai dubbed LZRD.
Akamai observed attacks in April targeting GeoVision devices through two OS command injection flaws - CVE-2024-6047 and CVE-2024-11120 - to download and run an ARM variant of Mirai dubbed LZRD.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.