{"id":4127,"date":"2022-03-31T20:30:49","date_gmt":"2022-04-01T01:30:49","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4127"},"modified":"2022-03-31T20:30:50","modified_gmt":"2022-04-01T01:30:50","slug":"muhstik-compromises-iot-devices","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/","title":{"rendered":"Muhstik compromises IoT devices"},"content":{"rendered":"\n<p>Although the Muhstik botnet has been around since at least 2018, by December 2019 Palo Alto Networks had identified a new variant of the botnet that attacked and took control of Tomato routers.<\/p>\n\n\n\n<p>Tomato firmware is well known, open and Linux based and is used by multiple router vendors as well as thousands of end-users who value its stability, VPN pass-through capability and advanced QoS control among other features. And back then, researchers searched Shodan for fingerprints, finding more than 4,600 exposed routers on the Internet.<\/p>\n\n\n\n<p>Now, cloud security company Lacework has provided some additional analysis and observations related to Muhstik attack is carried out in several stages.<\/p>\n\n\n\n<p>First, a payload file with the name &#8220;pty&#8221; followed by a number is downloaded from the attacker&#8217;s server. Sample URLs provided by Lacework include:<\/p>\n\n\n\n<p><strong><em>hxxp:\/\/159.89.156.190\/.y\/pty2<\/em><\/strong><br><strong><em>hxxp:\/\/167.99.39.134\/.x\/pty3<\/em><\/strong><\/p>\n\n\n\n<p>Once the installation is complete, Mushtik will contact the IRC channel to receive the commands.<\/p>\n\n\n\n<p>Lacework claims that the original malware samples were uploaded to VirusTotal all at once before the Muhstik attacks were seen in the wild, and that these samples had multiple strings mentioning &#8220;shenzhouwangyun&#8221;, as in: <\/p>\n\n\n\n<p>\/home\/wys\/ shenzhouwangyun\/shell\/downloadFile\/tomato.deutschland-zahlung.eu_nvr<\/p>\n\n\n\n<p>This indicates that &#8220;Shen Zhou Wang Yun is probably the creator of the malware and not just the first to upload it&#8221;, or at least that&#8217;s what experts believe.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some may remember the Muhstik botnet which attacked routers with Tomato firmware and today we will talk about this threat&#8230;&#8230;.<\/p>\n","protected":false},"author":1,"featured_media":4128,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4127","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Muhstik compromises IoT devices - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Some may remember the Muhstik botnet which attacked routers with Tomato firmware and today we will talk about this threat.......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Muhstik compromises IoT devices - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Some may remember the Muhstik botnet which attacked routers with Tomato firmware and today we will talk about this threat.......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-01T01:30:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-01T01:30:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Muhstik.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1500\" \/>\n\t<meta property=\"og:image:height\" content=\"844\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Muhstik compromises IoT devices\",\"datePublished\":\"2022-04-01T01:30:49+00:00\",\"dateModified\":\"2022-04-01T01:30:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/\"},\"wordCount\":228,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Muhstik.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/\",\"name\":\"Muhstik compromises IoT devices - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Muhstik.jpg\",\"datePublished\":\"2022-04-01T01:30:49+00:00\",\"dateModified\":\"2022-04-01T01:30:50+00:00\",\"description\":\"Some may remember the Muhstik botnet which attacked routers with Tomato firmware and today we will talk about this threat.......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Muhstik.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Muhstik.jpg\",\"width\":1500,\"height\":844},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muhstik-compromises-iot-devices\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Muhstik compromises IoT devices\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Muhstik compromises IoT devices - Truxgo Server Blog","description":"Some may remember the Muhstik botnet which attacked routers with Tomato firmware and today we will talk about this threat.......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/","og_locale":"es_MX","og_type":"article","og_title":"Muhstik compromises IoT devices - Truxgo Server Blog","og_description":"Some may remember the Muhstik botnet which attacked routers with Tomato firmware and today we will talk about this threat.......","og_url":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-04-01T01:30:49+00:00","article_modified_time":"2022-04-01T01:30:50+00:00","og_image":[{"width":1500,"height":844,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Muhstik.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Muhstik compromises IoT devices","datePublished":"2022-04-01T01:30:49+00:00","dateModified":"2022-04-01T01:30:50+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/"},"wordCount":228,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Muhstik.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/","url":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/","name":"Muhstik compromises IoT devices - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Muhstik.jpg","datePublished":"2022-04-01T01:30:49+00:00","dateModified":"2022-04-01T01:30:50+00:00","description":"Some may remember the Muhstik botnet which attacked routers with Tomato firmware and today we will talk about this threat.......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Muhstik.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Muhstik.jpg","width":1500,"height":844},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/muhstik-compromises-iot-devices\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Muhstik compromises IoT devices"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4127"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4127\/revisions"}],"predecessor-version":[{"id":4129,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4127\/revisions\/4129"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4128"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}