A Mirai variant rapidly spread by targeting ZyXEL PK5001Z routers affected by CVE-2016-10401, a backdoor account flaw that exposed hardcoded Telnet credentials and a hidden path to root access. After proof-of-concept exploit code was published, attackers began scanning ports 23 and 2323 at scale, logging in with credentials including admin/CenturyL1nk and admin/QwestM0dem, then using the device's built-in super-user capability to install Mirai malware on vulnerable internet-exposed routers.
Researchers reported nearly 100,000 unique scanning IPs over roughly 60 hours, with a large share of activity traced to Argentina, particularly networks associated with Telefonica de Argentina. Netlab linked the campaign to command-and-control servers at bigboatreps.pw:23 and blacklister.nl:23, and said the malware was distributed in multiple CPU-specific builds before both servers were later sinkholed by the security community. The vulnerable modem version cited in public exploit material was PK5001Z 2.6.20.19, a model used by CenturyLink.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Netlab reported nearly 100,000 unique scanner IPs over roughly 60 hours, with a heavy concentration in Argentina, and tied the outbreak to Telnet scanning on ports 23 and 2323. The report also disclosed command-and-control servers, malware hashes, and download URLs for multiple Mirai binaries.
Netlab reported that abuse of the admin/CenturyL1nk and admin/QwestM0dem credentials peaked during daytime on 2017-11-23. The timing and IP overlap supported the assessment that this credential abuse drove the broader scanning surge.
Researchers observed a new Mirai variant begin spreading around 2017-11-22 11:00 by scanning Telnet ports 23 and 2323 and abusing the credentials admin/CenturyL1nk and admin/QwestM0dem. The activity was linked to exploitation of exposed ZyXEL PK5001Z routers.
Exploit-DB published EDB-ID 43105 for CVE-2016-10401, documenting hardcoded Telnet credentials and a hardcoded root password in ZyXEL PK5001Z modems. The proof of concept showed remote Telnet access followed by privilege escalation to root.
An update to the Netlab report stated that both identified command-and-control servers, bigboatreps.pw:23 and blacklister.nl:23, had been sinkholed by the security community.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceblog.netlab.360.com
Open sourceexploit-db.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.