logo

TP-Link Router Botnet

ID: f455292e-7fd0-529b-b0f1-a0b0eff94f21

STIX ID: report--f455292e-7fd0-529b-b0f1-a0b0eff94f21

Feed Name: Schneier on Security

Threat Score
75/100

Date Published: 2025-03-14

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

A new botnet is exploiting a TP-Link Archer router vulnerability (CVE-2023-1389) to achieve command injection and remote code execution, infecting thousands of devices globally and used to distribute malware families including Mirai, Condi, and AndroxGh0st. Infections are concentrated in Brazil, Poland, the United Kingdom, Bulgaria and Turkey, with targeting observed against manufacturing, medical/healthcare, services and technology organizations in the United States, Australia, China and Mexico.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.