• News/
  • https://www.darkreading.com/endpoint-security/mirai-variant-aquabot-exploits-mitel-phone-flaws

Mirai Variant 'Aquabot' Exploits Mitel Device Flaws

Dark Reading
·
Elizabeth Montalbano
·
Published Jan 29, 2025
·
Updated

Yet another Mirai botnet variant is making the rounds, this time offering distributed denial-of-service (DDoS) as-a-service by exploiting flaws in Mitel SIP phones. It also features a unique capability to communicate with attacker command-and-control (C2). Researchers at the Akamai Security Intelligence and Response Team (SIRT) identified the variant of the infamous botnet, dubbed Aquabot, that actively exploits CVE-2024-41710, a command-injection vulnerability that affects various Mitel models that are used in corporate environments, they revealed in a blog post published Jan. 29. The vulnerability relies on an input sanitization flaw, and exploitation can lead to root access of the device, SIRT researchers Kyle Lefton and Larry Cashdollar wrote in the post. The variant is the third version of Aquabot (Akamai calls it Aquabotv3) to appear on the scene; the first version was built off the Mirai framework with the ultimate goal of DDoS, discovered in November 2023, and it was first reported by Antiy Labs. The second version of the bot "tacked on concealment and persistence mechanisms, such as preventing device shutdown and restart" that remain present in v3, the researchers wrote. The new variant is distinct from the previous versions for a couple of reasons, the researchers said. One is a unique feature appearing first in Aquabotv3: a function named "report_kill" that reports back to the C2 when a kill signal is caught on the infected device. So far, however, researchers have...

Read full article

Affected Software

3 affected components
Mitel SIP Phone=6869i
Mitel SIP Phone=6.3.0.1020
Mitel SIP Phones

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the Mirai variant 'Aquabot' which exploits vulnerabilities in Mitel SIP phones.

2

What security implications are discussed in the article?

The article highlights the risks of distributed denial-of-service (DDoS) attacks and the exploitation of vulnerable Mitel devices.

3

What products or software are affected by the Aquabot variant?

The affected products include specific Mitel SIP Phone models, namely the 6869i and version 6.3.0.1020.

4

How does the Aquabot variant communicate with its command and control servers?

The Aquabot variant features a unique capability to establish communication with attacker command-and-control servers.

5

What is the significance of the 'Aquabot' variant in relation to previous Mirai botnets?

Aquabot represents another evolution of the Mirai botnet, offering new functionalities and methods of exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203