Palo Alto Networks Unit 42 reported two previously unidentified command-injection vulnerabilities in internet-exposed IoT services that were actively exploited to deliver Mirai malware. One campaign abused an unsanitized NTP_SERVER HTTP parameter in a web service used to configure NTP settings, while the other targeted an unsanitized pid HTTP parameter in what researchers believe was a remote process management service. In successful intrusions, the attackers invoked wget to fetch a shell script that then downloaded and executed Mirai binaries built for multiple processor architectures.
Researchers observed the first campaign between July and September 2020 and a second burst of exploitation that generated 48 incidents in 12 seconds. Across both campaigns, four Mirai variants were deployed, all capable of DDoS activity, while one variant also carried worm-like propagation features that leveraged numerous known IoT and remote-code-execution exploits. The findings underscore the continued exposure created by unsupported IoT devices, and the report included indicators of compromise such as malware hashes, hosting IP addresses, and Mirai command-and-control domains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported that the first observed NTP_SERVER-based exploit campaign continued until Sept. 23, 2020. By the time of reporting, that campaign had generated 42 unique alerts.
On Aug. 16, 2020, Unit 42 observed a second command-injection campaign abusing the pid HTTP parameter, which researchers suspected targeted a remote process management service. The activity generated 48 attack incidents within 12 seconds and delivered additional Mirai variants.
Unit 42 first observed a command-injection campaign abusing the NTP_SERVER HTTP parameter to deliver Mirai malware to IoT devices. Successful exploitation triggered wget to fetch a shell script that downloaded and executed Mirai binaries for multiple architectures.
Palo Alto Networks Unit 42 disclosed its analysis of two in-the-wild exploit campaigns that delivered four Mirai variants, including one variant with worm-like propagation using numerous known IoT and RCE exploits. The report also published indicators of compromise such as malware hashes, hosting IPs, and Mirai C2 domains.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.