logo

'Ballista' Botnet Exploits 2023 Vulnerability in TP-Link Routers

ID: 898b3e36-a5eb-5693-8aac-f6c7425faf10

STIX ID: report--898b3e36-a5eb-5693-8aac-f6c7425faf10

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-03-12

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

A global IoT botnet campaign called "Ballista" is actively exploiting TP-Link Archer routers via CVE-2024-1389 to install malware that opens a TLS-encrypted C2 on port 82; researchers have observed exploitation attempts since early 2025, identified over 6,000 vulnerable devices across multiple countries and sectors, and noted indicators suggesting an Italian-based actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.