logo

Previously unidentified botnet infects unpatched TP-Link Archer home routers

ID: 63c665fe-3366-51cd-ae10-caaae2ed3859

STIX ID: report--63c665fe-3366-51cd-ae10-caaae2ed3859

Feed Name: The Record from Recorded Future News

Threat Score
72/100

Date Published: 2025-03-11

Date Updated: 2026-05-01

...
...

Cato Networks researchers identified Ballista, a new IoT botnet actively exploiting CVE-2023-1389 to infect TP-Link AX21/AX1800 routers worldwide; the malware fully compromises devices, establishes encrypted links, supports arbitrary command execution, can propagate automatically, and shows evolving stealth (including Tor-based C2) and possible data-theft capabilities, with thousands of vulnerable devices observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.