Palo Alto Networks Unit 42 reported two previously unidentified command-injection vulnerabilities in internet-exposed IoT services that were actively exploited to deliver Mirai malware. One campaign abused an unsanitized NTP_SERVER HTTP parameter in a web service used to configure NTP settings, while the other targeted an unsanitized pid HTTP parameter in what researchers believe was a remote process management service. In successful intrusions, the attackers invoked wget to fetch a shell script that then downloaded and executed Mirai binaries built for multiple processor architectures.
Researchers observed the first campaign between July and September 2020 and a second burst of exploitation that generated 48 incidents in 12 seconds. Across both campaigns, four Mirai variants were deployed, all capable of DDoS activity, while one variant also carried worm-like propagation features that leveraged numerous known IoT and remote-code-execution exploits. The findings underscore the continued exposure created by unsupported IoT devices, and the report included indicators of compromise such as malware hashes, hosting IP addresses, and Mirai command-and-control domains.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported that the first observed NTP_SERVER-based exploit campaign continued until Sept. 23, 2020. By the time of reporting, that campaign had generated 42 unique alerts.
On Aug. 16, 2020, Unit 42 observed a second command-injection campaign abusing the pid HTTP parameter, which researchers suspected targeted a remote process management service. The activity generated 48 attack incidents within 12 seconds and delivered additional Mirai variants.
Unit 42 first observed a command-injection campaign abusing the NTP_SERVER HTTP parameter to deliver Mirai malware to IoT devices. Successful exploitation triggered wget to fetch a shell script that downloaded and executed Mirai binaries for multiple architectures.
Palo Alto Networks Unit 42 disclosed its analysis of two in-the-wild exploit campaigns that delivered four Mirai variants, including one variant with worm-like propagation using numerous known IoT and RCE exploits. The report also published indicators of compromise such as malware hashes, hosting IPs, and Mirai C2 domains.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.