New Mukashi botnet is taking advantage of vulnerabilities in network-area storage devices made by Zyxel. Operators use brute-force methods to guess combinations of passwords and usernames to build the new botnet. Mukashi uses a custom decryption routine to encrypt commands and credentials, instead of the previous encryption methods used with Mirai. The company has issued a patch for the vulnerability, but NAS products that reached end-of-support in 2016 or earlier would not receive updates and could still be vulnerable.”]
Source: https://www.healthcareinfosecurity.com/new-mirai-variant-exploits-nas-device-vulnerability-a-14004