On Wednesday, December 11, 2024, several customers reported suspicious behavior on their Session Smart Network (SSN) platforms. These systems have been infected with the Mirai malware and were subsequently used as a DDOS attack source to other devices accessible by their network. The impacted systems were all using default passwords. Any customer not following recommended best practices and still using default passwords can be considered compromised as the default SSR passwords have been added to the virus database.
Key Features of Mirai Malware
Suspicious Network/TCP Activity Indicators
When monitoring for potential Mirai activity, here are some suspicious signs to look for:
Next Steps for Prevention
By staying vigilant and implementing these best practices, organizations can reduce their risk of falling victim to Mirai and similar malware.
Resources:
Password help and best practices:
https://www.juniper.net/documentation/us/en/software/session-smart-router/docs/cc_fips_config_password_policies/#password-requirements
Please see above.
What to do if a system is infected:
If a system is found to be infected, the only certain way of stopping the threat is by reimaging the system as it cannot be determined exactly what might have been changed or obtained from the device.