A new variant of the Mirai-based botnet malware Aquabot has been observed actively exploiting CVE-2024-41710, a command injection vulnerability in Mitel SIP phones. The activity was discovered by Akamai's Security Intelligence and Response Team (SIRT), who reports that this is the third variant of Aquabot that falls under their radar. The malware family was introduced in 2023, and a second version that added persistence mechanisms was released later. The third variant, 'Aquabotv3,' introduced a system that detects termination signals and sends the info to the command-and-control (C2) server. Akamai comments that Aquabotv3's mechanism to report back kill attempts is unusual for botnets and may have been added to give its operators better monitoring. CVE-2024-41710 is a command injection flaw impacting Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, typically used in corporate offices, enterprises, government agencies, hospitals, educational institutes, hotels, and financial institutions. It is a medium-severity flaw that allows an authenticated attacker with admin privileges to conduct an argument injection attack due to insufficient parameter sanitization during the boot process, resulting in arbitrary command execution. Mitel released fixes and a security advisory about this flaw on July 17, 2024, urging users to upgrade. Two weeks later, security researcher Kyle Burns published a proof-of-concept (PoC) on GitHub. Aquabotv3's use of this PoC to exploit CVE-2024...
New Aquabotv3 botnet malware targets Mitel command injection flaw
BleepingComputer
·Bill Toulas
·Published Jan 30, 2025
·Updated
Affected Software
6 affected components
Mitel 6800 Series SIP Phones
Mitel 6900 Series SIP Phones
Mitel 6900w Series SIP Phones
Mitel SIP Phones=6800 Series
Mitel SIP Phones=6900 Series
Mitel SIP Phones=6900w Series
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new variant of the Aquabot botnet exploiting a command injection vulnerability in Mitel SIP phones.
2
What security implications are discussed?
The article highlights the potential for exploitation of the CVE-2024-41710 vulnerability, which can lead to unauthorized access and control over affected systems.
3
What software or products are specifically affected?
The affected products include Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones.
4
How was the vulnerability discovered?
The vulnerability's exploitation was discovered by Akamai's Security Intelligence team.
5
What type of malware is being discussed in relation to the vulnerabilities?
The article refers to a variant of Mirai-based malware known as Aquabotv3.