AndoryuBot's DDOS Rampage
ID: 6441a81c-c952-5ab8-af3f-ce315a631f7c
STIX ID: report--6441a81c-c952-5ab8-af3f-ce315a631f7c
Feed Name: Cyble Blog
Threat Score
This report documents active exploitation of CVE-2023-25717 — a critical Ruckus Wireless Admin RCE — by the AndoryuBot botnet. It includes malware analysis (SHA256 and runtime behavior), confirms public PoC availability and CISA KEV listing, estimates ~52,000 internet-exposed Ruckus admin panels, and provides IoCs (malicious IPs, URLs, and file hashes); recommended mitigations include patching, segmentation, and continuous monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
