A new variant of the Mirai-based malware Aquabot is actively exploiting a vulnerability in Mitel phones to build a remote-controlled botnet, according to Akamai's Security Intelligence and Response Team. In case an army of office phones firing off distributed denial of service (DDoS) attacks against individuals or critical organizations isn't concerning enough, this latest strain, dubbed Aquabotv3, apparently has a never-seen-before capability that reports back to its command-and-control server when it catches a kill signal – an attempt to terminate the malware – on an infected device. "We haven't seen this behavior before in a Mirai variant so perhaps it may become a new feature," Akamai's Kyle Lefton and Larry Cashdollar said. "Although the true reason for this behavior has not been confirmed, this communication to the C2 could be a way for the botnet author to actively monitor the botnet's health," the duo wrote Tuesday. Aquabot, which is based on the Mirai framework, allows miscreants to remotely control infected equipment, and is built for launching DDoS attacks at selected targets. This particular botnet has been around since at least November 2023, and now there are three publicly known versions of the malware. Based on its analysis, Akamai determined Aquabotv3 to be a new variant, primarily due to its new functions. In addition to the typical DDoS attack capabilities, the Aquabotv3 has a function that sets up a signal handler to check for several kill signals. If any ...
Why is my Mitel phone DDoSing strangers? Oh, it was roped into a new Mirai botnet
The Register
·Jessica Lyons
·Published Jan 29, 2025
·Updated
Affected Software
5 affected components
Mitel 6800=R6.4.0.HF1
Mitel 6900=R6.4.0.HF1
Mitel 6900w=R6.4.0.HF1
Mitel 6970 Conference Unit=R6.4.0.HF1
Mitel phones
Frequently Asked Questions
1
What is the main issue addressed in the article?
The article discusses a new variant of the Mirai botnet, called Aquabot, exploiting vulnerabilities in Mitel phones.
2
What is the impact of the Aquabot malware on Mitel devices?
The Aquabot malware is turning Mitel phones into part of a remote-controlled botnet that can conduct DDoS attacks.
3
Who reported the exploit affecting Mitel phones?
The exploit was reported by Akamai's Security Intelligence and Response Team.
4
Which specific Mitel phone models are mentioned as being affected?
The affected models include the Mitel 6800, 6900, 6900w, and 6970 Conference Unit, all running version R6.4.0.HF1.
5
What security measures should users of affected Mitel phones consider?
Users should urgently update their devices to secure versions to protect against the Aquabot exploit.