logo

Zerobot Malware Exploits Tenda Command Injection Vulnerabilities to Deploy Malicious Payloads

ID: f747336b-eac7-5802-a340-2ec988e35122

STIX ID: report--f747336b-eac7-5802-a340-2ec988e35122

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A Zerobot campaign is actively exploiting CVE-2025-7544 (unauthenticated stack overflow in Tenda AC1206) and CVE-2025-68613 (n8n workflow RCE) to deploy a Mirai-based multi-architecture botnet named Zerobotv9. Attackers use simple HTTP requests and embedded commands to fetch a multi-stage loader (tol.sh) which retrieves UPX-packed binaries and contacts hard-coded C2 domains; observed behaviors include DDoS routines and expanded attack modules. The report includes observed exploit activity, IOCs (C2 domain and download patterns), and recommended mitigations for router administrators and n8n operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.