Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers
ID: 6a50d8f3-3fa8-5d0b-afaf-1e8f7fbd883b
STIX ID: report--6a50d8f3-3fa8-5d0b-afaf-1e8f7fbd883b
Feed Name: Security Affairs
Threat Score
Akamai SIRT observed active exploitation of CVE-2025-29635 (command injection) in discontinued D-Link DIR-823X routers by Mirai botnet variants; the report includes firmware reverse engineering, PoC-based exploitation details, a 'tuxnokill' Mirai payload (XOR-encoded, C2 IPs), IoCs and YARA rules, and recommends patching/upgrading vulnerable devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
