A botnet of 13,000 MikroTik devicesis using a misconfiguration in domain name server records to bypass email protections and deliver malware by spoofing approximately 20,000 web domains.
See also: New botnet targets industrial routers with zero-day exploits

The malicious actor exploits a misconfigured DNS record for the Sender Policy Framework (SPF) which is used to list all servers authorized to send email messages on behalf of a domain.
According to DNS security firm Infoblox, the malspam campaign was active in late November 2024. Some of the emails impersonated shipping company DHL Express and delivered fake freight invoices with a ZIP file containing a malicious payload.
Inside the ZIP attachment was a JavaScript that compiles and executes a PowerShell script. The script establishes a connection to the threat's command and control (C2) server on a domain previously associated with Russian hackers.
Infoblox explains that DNS SPF records for approximately 20,000 domains were configured with the overly permissive “+all” option, which allows any server to send emails on behalf of those domains.
See also: Malware botnets exploit outdated D-Link routers
A more secure option is to use the “-all” option, which restricts email sending to the servers specified by the domain.

The method of compromise remains unclear, but Infoblox says it “saw a variety of versions affected, including recent [MikroTik] firmware releases.” MikroTik routers are known to be powerful, and threat actors have targeted them to create botnets capable of very powerful attacks.
Despite urging MikroTik device owners to update their systems, many of the routers remain vulnerable for extended periods of time due to the very slow patch update rate.
The botnet in this case configured the devices as SOCKS4 to carry out DDoS attacks, send phishing, exploit data, and generally help hide the origin of malicious traffic.
See also: Mirai Botnet targets Juniper smart routers
Botnets, such as the one used by MikroTik devices, are networks of compromised computers or devices that are remotely controlled by attackers, often without the knowledge of the users. These networks are typically used to perform malicious activities, such as sending spam, conducting distributed denial-of-service (DDoS) attacks, stealing sensitive information, or spreading malware. A botnet works by infecting devices with malware, turning them into “bots” that follow the commands of a central controller, known as a botmaster. With the increasing number of connected devices, botnets have become a significant cybersecurity threat ,highlighting the need for strong security practices to protect systems from compromise.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
