logo

MikroTik botnet uses misconfigured SPF DNS records to spread malware

ID: 8132afb1-fcdf-50b3-af14-4d40d5955f4d

STIX ID: report--8132afb1-fcdf-50b3-af14-4d40d5955f4d

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-01-15

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Infoblox discovered an active malspam campaign that leverages misconfigured SPF records (+all) across ~20,000 domains to spoof senders and deliver malicious ZIP attachments; ~13,000 compromised MikroTik routers were configured as SOCKS4 proxies to relay phishing emails, enable large-scale DDoS, and hide attacker infrastructure, with payloads executing PowerShell connecting to a C2 domain linked to Russian hackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.