logo

Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware

ID: 31e05337-7d0e-5751-9cd3-097b892bf795

STIX ID: report--31e05337-7d0e-5751-9cd3-097b892bf795

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A resurfaced Mirai-based botnet variant, zerobotv9, is actively exploiting critical RCE vulnerabilities in Tenda AC1206 routers and the n8n workflow automation platform to deploy a UPX-packed Mirai payload; researchers observed exploitation in mid-January 2026, identified C2 infrastructure (0bot.qzz.io) and several malicious IPs, and provided IoCs and mitigation guidance including patching, upgrades, and network blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.