According to a blog post from IT security company Palo Alto Networks, a new variant of the IoT/Linux botnet Tsunami, which it calls Amnesia, targets an unpatched remote code execution vulnerability that was publicly disclosed over a year ago in DVR devices manufactured by TVT Digital and branded by over 70 vendors worldwide.
“Reports of another botnet variant exploiting the Internet of Things for nefarious activities, such as large-scale DDoS attacks, comes as no surprise. Whilst Mirai simply exploited default credentials to gain access to devices, the reported exploitation of a specific code vulnerability, by what is being called the “Amnesia” botnet, is a natural progression for attackers looking for other simple methods of compromising these typically poorly secured devices. The fact that the malware used to create this botnet has security evasion techniques built-in, is a stark indication of the value such botnets create for the perpetrators, showing they will put in the extra effort necessary to ensure their success. This is in contrast to the IoT vendors for whom, without regulation or public pressure, there is no motivation to put additional effort and resources into ensuring their devices are well secured and that their software is vigorously examined for potential vulnerabilities.”
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.