Mitel SIP Phones may be at risk, according to Cybersecurity company Akamai, as its threat intelligence team discovered a malware that is "actively attempting to exploit Mitel SIP phones."
"This malware exhibits a behavior we have never before seen with a Mirai variant,"
The blog said.
Akamai released their findings on 28 January on a blog, outlining the details of evidence of active exploits and how the significant security threat leaves Mitel SIP phones vulnerable to attack.
The Threat
The Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based malware, dubbed Aquabotv3, which is actively attempting to exploit Mitel SIP phones.
This malware exploits CVE-2024-41710, a command injection vulnerability affecting various Mitel models.
The vulnerability was discovered by a researcher at penetration testing company Packetlabs in August 2024.
A proof of concept (PoC)—a practical demonstration of how the vulnerability in Mitel SIP phones could be exploited, was found to affect Mitel 6800, 6900, and 6900w series SIP phones, including the 6970 Conference Unit.
The flaw relies on an input sanitisation issue—how the device handles and processes user-supplied input—and its exploitation can lead to root access to the device.
Root access to the device means an attacker gains complete control over the system, allowing it to read messages it receives, access contact information, change things like passwords, or even use it to launch a wider attack on the company's SIP phone systems.
Following the discovery, Mitel released an update to their software.
Active Exploitation
Since the exploit was found, Akamai SIRT has detected exploit attempts targeting this vulnerability.
Having a global network of honeypots—decoy systems or servers set up to attract attackers and monitor malicious activity—the SIRT saw attempts made in January 2025.
The payload used in these attempts was almost identical to the PoC found in August 2024 but was instead, this time, being used to spread malware.
The Threat: Aquabotv3
Based on Akamai's analysis of the malware samples, they determined that this is a version of the Aquabot Mirai variant.
Aquabot is a botnet—a network of compromised internet-connected devices that have been infected with malware— built on the Mirai malware framework and is designed primarily for launching distributed denial-of-service (DDoS) attacks.




