Security

Mirai variant turns TalkTalk routers into zombie botnet agents

Infosec folk spot web of compromised British devices

By John Leyden

35 SHARE

Hundreds of Mirai-infected home routers across the UK are currently acting as DDoS bots.

The vast majority (99 per cent) of these 2,398 Mirai-infected devices are TalkTalk routers, according to security researchers at DDoS mitigation firm Imperva Incapsula.

“The botnet devices’ geolocation is very uncommon for DDoS botnets and indicates a vulnerability in a locally distributed device, which allows for such a regional botnet to appear,” Imperva Incapsula warns.

“Without full access to the infected routers, it’s difficult to know with certainty whether the malware used to execute this attack was the same Mirai variant used against Deutsche Telekom or the one encountered by the BadCyber researchers.”

More details on the problem can be found in a blog post by Imperva Incapsula here.

In response, TalkTalk said the situation was in hand:

Along with other ISPs in the UK and abroad, we continue to take steps to review the potential impacts of the Mirai worm. A small number of customer routers are affected by this issue. We have made good progress repairing these, and replacing them when necessary, and we continue to deploy additional network-level controls to further protect our customers.

®

Sign up to our NewsletterGet IT in your inbox daily

35 Comments

More from The Register

ISP popped router ports, saving customers the trouble of making themselves hackable

SingTel then left them open for a while, because ... well there's no excuse is there?

Harassment, hate and bile, suicide instructions for kids... anything else social media's good at? Ah yes, cybercrime

Businesses as well as ordinary punters hit by viral nasties

ISP TalkTalk's Wi-Fi passwords Walk Walk thanks to Awks Awks router security hole

Brit broadband biz has only had four years to patch up WPS

Begone, Demon Internet: Vodafone to shutter old-school pioneer ISP

Exclusive It was still going?

TP-Link 'smart' router proves to be anything but smart – just like its maker: Zero-day vuln dropped after silence

Google security engineer emits SR20 PoC exploit after manufacturer fails to respond

Android PDF app with just 100m downloads caught sneaking malware into mobes

Scram CamScanner, says Kaspersky

Airbnb host thrown in the clink after guest finds hidden camera inside Wi-Fi router

Perv messed with the wrong woman – an IT security bod

Oracle 'net-watcher agrees, China Telecom is a repeat offender for misdirecting traffic

Network admins really need to mind their MANRS

Bank-account-raiding Goznym malware bust: Five suspects collared, five still on the run. $100m feared stolen

Most exciting Enid Blyton book yet – Five accused of international fraud?

Huawei's half-arsed router patching left kit open to botnets: Chinese giant was warned years ago – then bungled it

Exclusive ISP alerted biz to UPnP flaw in 2013. Years later, same flaw kept cropping up