Researchers Warns on an attack surge of Realtek Vulnerability
Researchers have reported a surge in the number of attacks that attempted to exploit a Realtek Jungle SDK RCE that is tracked as CVE-2021-35394 with a CVSS score of 9.8. Nearly 134 million exploit attempt was made till last month – December 2022.
Realtek Jungle SDK version v2.x through v3.4.14B provides a diagnostic tool called ‘MP Daemon’ that is usually compiled as a ‘UDPServer’ binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
The experts warned that the attacks conducted by multiple threat actors are still ongoing. Many of these attacks attempted to deliver malware to vulnerable IoT devices. Most of the malware samples belong to Mirai, Gafgyt, and Mozi families.
Researchers observed a new distributed IoT DDoS botnet developed in Golang, tracked as RedGoBot.
- In the first campaign observed in early September 2022, when the threat actor tried to deliver a shell script znet.sh downloader from 185.216.71[.]157 utilizing wget.
- In the second campaign, which was observed in November 2022, when the threat actor used a shell script with wget and curl to download the following botnet clients from 185.246.221[.]220
The analysis of the attacks in the wild revealed the use of the following three types of payloads:
- A script executes a shell command on the targeted server (mostly from the Mirai).
- An injected command directly writes the binary payload to a file and then executes it.
- An injected command directly reboots the targeted server to trigger a denial-of-service condition
The flaw affects almost 190 models of devices from 66 different manufacturers and the origin from the U.S., Vietnam, and Russia. But the use of Proxy VPN is also not ruled out. This surge can result in a possible supply chain attack which is difficult to detect and remediate.
This research was documented by researchers for Palo Alto
Indicators of Compromise