Check Point Research disclosed active exploitation of a zero-day command injection flaw in Huawei HG532 home routers, tracked as CVE-2017-17215, after detecting widespread attacks against port 37215. The exploit was used to install OKIRU/SATORI, an updated Mirai variant that converts compromised routers into DDoS bots and communicates with its command-and-control infrastructure over a custom protocol. Researchers said the activity was observed globally, with notable concentrations in the United States, Italy, Germany, and Egypt.
Huawei issued a patch after coordinated disclosure, while Check Point linked the campaign to a suspected actor using the nickname "Nexus Zeta" based on domain registration and online persona overlaps. The researchers assessed the operator as relatively unskilled despite leveraging a zero-day exploit, underscoring how leaked botnet code and exposed IoT devices can enable large-scale botnet recruitment and downstream denial-of-service operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2017-12-21, Check Point Research published details of the Huawei HG532 exploitation campaign, the associated OKIRU/SATORI malware, and its assessment that the suspected operator was linked to the nickname "Nexus Zeta." The report characterized the actor as relatively unskilled despite using a zero-day exploit.
After Check Point's coordinated disclosure, Huawei quickly released a fix for the HG532 command injection flaw tracked as CVE-2017-17215. This patch addressed the vulnerability being actively exploited in the botnet recruitment campaign.
On 2017-12-05, Netlab 360 warned that the Satori Mirai variant was spreading in worm-like fashion using both TCP port 37215 and port 52869. This added technical detail suggested the botnet was leveraging more than the already documented Huawei HG532 exploitation path.
The exploitation campaign delivered OKIRU/SATORI, an updated Mirai variant that enrolled infected Huawei routers into a DDoS botnet and communicated with its command-and-control server using a custom protocol. Check Point reported attack activity globally, with notable concentrations in the United States, Italy, Germany, and Egypt.
On 2017-11-23, Check Point observed widespread exploitation attempts against TCP port 37215 on Huawei HG532 home routers. The activity used a command injection zero-day later tracked as CVE-2017-17215.
6 references tracked. Mallory keeps watching after this page renders.
theregister.co.uk
Open sourcebleepingcomputer.com
Open sourceresearch.checkpoint.com
Open sourceics-cert.kaspersky.com
Open sourcearstechnica.com
Open sourceblog.netlab.360.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.