logo

Beyond the Router: How the Zerobotv9 Botnet is Hijacking Enterprise Automation

ID: 3cfc149c-0203-5755-b6e0-af2b8017ac74

STIX ID: report--3cfc149c-0203-5755-b6e0-af2b8017ac74

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-23

Author: Ddos

...
...

Akamai SIRT observed Zerobotv9 — a Mirai-based botnet variant — actively exploiting two publicly disclosed vulnerabilities (CVE-2025-7544 in Tenda AC1206 routers and CVE-2025-68613 in the n8n automation platform) to install a payload (tol.sh); the shift to targeting n8n raises risk of lateral movement and theft of sensitive credentials in corporate environments, with attacks detected in mid‑January 2026 and public fixes available for the flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.