Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware
ID: 31e05337-7d0e-5751-9cd3-097b892bf795
STIX ID: report--31e05337-7d0e-5751-9cd3-097b892bf795
Feed Name: cybersecurityNews.com
Threat Score
A resurfaced Mirai-based botnet variant, zerobotv9, is actively exploiting critical RCE vulnerabilities in Tenda AC1206 routers and the n8n workflow automation platform to deploy a UPX-packed Mirai payload; researchers observed exploitation in mid-January 2026, identified C2 infrastructure (0bot.qzz.io) and several malicious IPs, and provided IoCs and mitigation guidance including patching, upgrades, and network blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
