At least six different malicious botnet operations are targeting TP-Link Archer AX21 (AX1800) that are vulnerable to a command injection that was reported and addressed last year.
See also: RUBYCARP hackers: New botnet attacks

Known as CVE-2023-1389, the flaw is a high-severity unauthenticated command injection issue in the local API, accessible through the TP-Link Archer AX21.
Several researchers discovered it in January 2023 and reported it to the vendor through the Zero-Day Initiative (ZDI). TP-Link addressed the issue by releasing firmware security updates in March 2023. The Proof-of-concept appeared shortly after the security advisory was released.
After that, cybersecurity teams warned of several botnets, including three Mirai variants and a botnet named “ Condi ,” which targeted unpatched TP-Link devices
Yesterday, Fortinet issued another warning saying it had noticed an increase in malicious activity exploiting the vulnerability, noting that it was coming from six botnet operations.
Fortinet telemetry data shows that since March 2024, daily infection attempts with CVE-2023-1389 have frequently exceeded 40,000 and reached 50,000.
Each of these botnets uses different methods and scenarios to exploit the vulnerability in TP-Link devices, establish control over the compromised devices, and command them to engage in malicious activities, such as distributed denial of service (DDoS) attacks.
See also: Increased botnet activity in the last month

- AGoent: Downloads and runs scripts that retrieve and execute ELF files from a remote server and then deletes the files to hide its tracks.
- Gafgyt Variant : Specializes in DDoS attacks by downloading scripts to execute Linux binaries and maintaining persistent connections to C&C servers.
- Moobot: Known for launching DDoS attacks, it retrieves and executes a script to download ELF files, executes them based on the architecture, and then removes the traces.
- Miori: Uses HTTP and TFTP to download ELF files, executes them, and uses hard-coded credentials for brute force attacks.
- Mirai Variant: Downloads a script that then retrieves ELF files, which are compressed using UPX. Monitors and terminates packet analysis tools to avoid detection.
- Condi: Uses a download script to improve infection rates, prevents device reboots to maintain stability, and scans and terminates specific processes to avoid detection.
Fortinet's report says that despite the vendor releasing a security update last year, a significant number of users continue to use outdated firmware.
TP-Link Archer AX21 (AX1800) router users are advised to follow the vendor's firmware upgrade instructions, available here, to protect themselves from botnets. They should also change the default admin passwords to something unique and long, and disable web access to the admin panel if not needed.
See also: FBI “broke down” Moobot botnet used by Russian hackers
How can someone protect themselves from Botnets?
To protect yourself from Botnets, you must first keep your software up to date. This includes your operating system, web browser, and any applications you use. Updates often include security patches that can prevent Botnets from attacking. In addition, using a reliable antivirus is essential. These programs can detect and remove the malicious code that Botnets use to control your computer. It is also important to be careful with the emails and messages you receive. Many Botnets spread through seemingly harmless messages that contain malicious links or attachments. Finally, using a virtual private network (VPN) can help protect you from Botnets.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
