Zerobot Malware Exploits Tenda Command Injection Vulnerabilities to Deploy Malicious Payloads
ID: f747336b-eac7-5802-a340-2ec988e35122
STIX ID: report--f747336b-eac7-5802-a340-2ec988e35122
Feed Name: GBHackers
A Zerobot campaign is actively exploiting CVE-2025-7544 (unauthenticated stack overflow in Tenda AC1206) and CVE-2025-68613 (n8n workflow RCE) to deploy a Mirai-based multi-architecture botnet named Zerobotv9. Attackers use simple HTTP requests and embedded commands to fetch a multi-stage loader (tol.sh) which retrieves UPX-packed binaries and contacts hard-coded C2 domains; observed behaviors include DDoS routines and expanded attack modules. The report includes observed exploit activity, IOCs (C2 domain and download patterns), and recommended mitigations for router administrators and n8n operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
