Unupdated TP-Link Archer routers are being used by a new botnet named Ballista.

As researchers Ofek Vardi and Matan Mittelman of Cato CTRL explained , the botnet exploits a very serious vulnerability ( CVE-2023-1389 ) that allows remote code execution (RCE) and affects TP-Link Archer AX-21 routers.
Cato CTRL said it detected the Ballista botnet campaign on January 10. The most recent exploitation attempt was recorded last month, on February 17.
See also: Edimax Camera Zero-Day Exploited by Botnets
The attack involves the use of a malware dropper, a shell script (“dropbpb.sh”) designed to retrieve and execute the main binary on the target system, for various system architectures such as mips, mipsel, armv5l, armv7l, and x86_64.
Once executed, the malware creates an encrypted command and control (C2) channel on port 82in order to take control of the device.
“This allows shell commands to be executed to conduct further RCE and DoS,” the researchers said. “In addition, the malware attempts to read sensitive files on the local system.”
Some of the commands supported by the Ballista botnet are:
- flooder: causes flood attack
- exploiter: exploits CVE-2023-1389
- start: optional parameter used with the exploiter to start the module
- shell: executes a Linux shell command on the local system
- killall: used to terminate the service
See also: Eleven11bot botnet has infected 86,000 devices for DDoS attacks
Additionally, the botnet is able to terminate its previous instances and delete its own instance once execution begins. It is also designed to spread to other routers in an attempt to exploit the vulnerability.

Experts believe that the operators of the Ballista botnet are likely Italian. The malware also appears to be under active development.
According to Censys, more than 6,000 devices have been infected by the Ballista botnet.
Botnet protection
To protect against this threat, it is important to software and operating system your device's. Botnet attacks often exploit known vulnerabilities.
It is also essential to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Vo1d malware botnet targets more and more Android TVs
Using strong passwords and changing them regularly is another way to protect yourself from Botnets. Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect your accounts.
Finally, information security training can be particularly useful. Understanding how botnet attacks work can help you identify and avoid attacks.
Source: thehackernews.com
