logo

Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts

ID: edf7903d-5403-5e42-97b7-22c808be7713

STIX ID: report--edf7903d-5403-5e42-97b7-22c808be7713

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Unit42 and other researchers observed large-scale automated exploitation of CVE-2023-33538 in end-of-life TP-Link routers (models TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10). Attackers inject commands into the router web interface to download and execute an arm7 Condi (Mirai-like) binary from 51.38.137.113 and connect to C2 cnc.vietdediserver.shop; the binary includes hard-coded IP/port, multi-architecture self-update behavior, and an embedded HTTP server to propagate to other devices. TP-Link confirms the devices are EOL with no patch forthcoming and recommends replacement, credential changes, and monitoring for malicious outbound traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.