logo

Botnets Continue Exploiting CVE-2023-1389 for Wide-Scale Spread

ID: 9f44aa44-34b7-5af7-bee6-e66fcf9ab8e4

STIX ID: report--9f44aa44-34b7-5af7-bee6-e66fcf9ab8e4

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2024-04-16

Date Updated: 2026-04-27

...
...

Fortinet Labs documents ongoing exploitation of TP-Link Archer AX21's CVE-2023-1389 by multiple IoT botnets (AGoent, Gafgyt variant, Moobot, Mirai variants, Miori, Condi), providing technical infection details, malware behaviors (user creation, C2 communication, DDoS modules), extensive IOCs (C2 domains, IPs, URLs, many file hashes), and mitigation guidance including FortiGuard detections and the importance of applying vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.