ELEVEN11 Botnet Mirai Variant Targeting NVMS-9000 Devices

Listen to this Post

The ELEVEN11 botnet, a Mirai variant, has been identified as the culprit behind a significant DDoS attack that disrupted X/Twitter for 1-2 days. This botnet has compromised around 400,000 devices globally, with 80,000 located in the U.S. The primary targets are TVT-NVMS-9000/RST recorders, exploiting control ports such as 1700, 6036, and 17001. The botnet leverages a TCP payload to query sensitive credentials and hardware versions, specifically using the `queryBasicCfg` command.

You Should Know: