Previously unidentified botnet infects unpatched TP-Link Archer home routers
ID: 63c665fe-3366-51cd-ae10-caaae2ed3859
STIX ID: report--63c665fe-3366-51cd-ae10-caaae2ed3859
Feed Name: The Record from Recorded Future News
Threat Score
Cato Networks researchers identified Ballista, a new IoT botnet actively exploiting CVE-2023-1389 to infect TP-Link AX21/AX1800 routers worldwide; the malware fully compromises devices, establishes encrypted links, supports arbitrary command execution, can propagate automatically, and shows evolving stealth (including Tor-based C2) and possible data-theft capabilities, with thousands of vulnerable devices observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
