Re: Mirai botnet is back — now as "Meris"

Brandon Svec bsvec at teamonesolutions.com
Thu Sep 9 16:55:47 UTC 2021


Oof.  I wonder if there is any connection to their DDNS service outage a
couple days ago?
https://forum.mikrotik.com/viewtopic.php?t=178256
*Brandon Svec*



On Thu, Sep 9, 2021 at 2:43 AM Töma Gavrichenkov <ximaera at gmail.com> wrote:

> Peace,
>
> An undisclosed (or, even, yet undiscovered by the vendor)
> vulnerability in SOHO Mikrotik routers seems to be exploited by
> someone.
> Approx. 328 thousand devices already joined the botnet, with each
> having unrestricted access to the uplink (up to 1 Gbps).  42,6% of
> exploited devices reside in the U.S.
>
> https://blog.qrator.net/en/meris-botnet-climbing-to-the-record_142/
>
> I didn't know Mikrotik was so popular in North America!
> Patching all those SOHO WiFi routers must be fun...
>
> --
> Töma
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20210909/865671c6/attachment.html>


More information about the NANOG mailing list