logo

New Mirai campaign exploits RCE flaw in EoL D-Link routers

ID: 9d5b0797-7d5d-5977-b7ea-bae75e14300f

STIX ID: report--9d5b0797-7d5d-5977-b7ea-bae75e14300f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Bill Toulas

...
...

Akamai SIRT detected active exploitation of D-Link DIR-823X command-injection CVE-2025-29635 in March 2026 where attackers send POST requests to download and execute a shell script that installs a Mirai-based botnet called "tuxnokill" (multi-architecture, DDoS capabilities); the campaign also leverages RCEs in TP-Link and ZTE devices, and affected routers are end-of-life making patches unlikely — users are advised to upgrade, disable remote admin, and change default credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.