Affected platforms
The following platforms are known to be affected:
Threat details
Miori can spread via exploitation of a ThinkPHP remote code execution vulnerability or by brute-force attacks on open Telnet ports.
Once access has been gained, Miori will attempt to connect to a command and control server (C2) using a text-based protocol for encryption, rather than the binary-based version used by other Mirai variants. Affected hosts are then enrolled into a botnet, which is then used to perform distributed denial of service attacks. Miori can also be used to execute malicious scripts on hosts.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Telnet is inherently insecure and has been superseded by several other protocols, including SSH. If Telnet is not required, then port 23 (TCP) should be closed.
To protect against a distributed denial-of-service (DDoS) attack, organisations should ensure:
Should an organisation suspect it is subject to an active DDoS attack, they should ensure that every effort is made to stop the attack and restore service. However, care should be taken to ensure that the attackers are not using the DDoS attack as a distraction whilst other, potentially more sensitive, systems are exploited. Monitoring of critical systems is recommended, including the use of host-based intrusion prevention and detection systems (HIPS/HIDS) where appropriate. |
CVE Vulnerabilities
Last edited: 14 February 2020 2:53 pm