logo

Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers

ID: 6a50d8f3-3fa8-5d0b-afaf-1e8f7fbd883b

STIX ID: report--6a50d8f3-3fa8-5d0b-afaf-1e8f7fbd883b

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Akamai SIRT observed active exploitation of CVE-2025-29635 (command injection) in discontinued D-Link DIR-823X routers by Mirai botnet variants; the report includes firmware reverse engineering, PoC-based exploitation details, a 'tuxnokill' Mirai payload (XOR-encoded, C2 IPs), IoCs and YARA rules, and recommends patching/upgrading vulnerable devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.