logo

New ShadowV2 botnet malware used AWS outage as a test opportunity

ID: 96c9d81f-c760-5cab-969a-966034a94d88

STIX ID: report--96c9d81f-c760-5cab-969a-966034a94d88

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-11-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ShadowV2 is a Mirai-based IoT botnet observed by FortiGuard that leveraged at least eight known vulnerabilities (affecting D-Link, TP-Link, DD-WRT, DigiEver, TBK, etc.) to infect routers, NAS devices and DVRs globally; it used a downloader (binary.sh) fetched from 81.88.18.108 and a C2 at 198.199.72.27 to deliver a Mirai-like binary supporting multiple UDP/TCP/HTTP DDoS flood types, with Fortinet publishing IoCs and urging firmware updates and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.