Juniper Networks has issued an urgent advisory following reports of Mirai malware infections targeting Session Smart Routers (SSRs) left with default passwords.
The campaign, first detected on December 11, exploited weak security practices to compromise devices and use them in distributed denial-of-service (DDoS) attacks.
The Mirai malware, notorious for its ability to exploit Internet of Things (IoT) devices, scans for systems using default login credentials.
Once access is gained, it executes commands remotely, enabling a wide range of malicious activities. In this case, compromised SSRs were weaponized to flood targeted networks with junk traffic, disrupting services and causing significant operational challenges.
This vulnerability impacts all versions of Session Smart Routers. According to Juniper’s advisory, the affected devices share a critical commonality: failure to replace factory-set credentials.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
The default SSR passwords have now been added to the malware’s database, making any system still using them highly susceptible to infection.
Administrators are advised to monitor their networks for signs of potential Mirai activity, including:
Mirai is infamous for its ability to turn IoT devices into botnets—networks of infected devices controlled remotely. Originally surfacing in 2016, it has since evolved into numerous variants.
The malware’s primary tactic involves exploiting weak credentials and software vulnerabilities to infiltrate devices. Once infected, these systems become tools for DDoS attacks or other malicious activities.
Juniper Networks recommends immediate action to prevent further infections:
For already compromised systems, Juniper advises reimaging the affected routers. This is the only guaranteed way to eliminate the malware and secure the device.
The incident underscores the critical importance of adhering to cybersecurity best practices. Weak password management remains a leading cause of IoT vulnerabilities, as demonstrated by this attack on SSRs.
Organizations must prioritize robust security measures to safeguard their networks against evolving threats like Mirai. By taking proactive steps now, businesses can mitigate risks and protect their infrastructure from similar attacks in the future.
2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…