HomeSecurityNew Botnet Exploits DNS Misconfiguration

New Botnet Exploits DNS Misconfiguration

A first-of-its-kind botnet campaign emerged in late November, using an innovative combination of DNS misconfiguration and compromised network devices to push a global malicious spam operation. Initial reports emerged when dozens of organizations received what appeared to be legitimate shipping invoices, each containing a ZIP file with a malicious JavaScript payload.

See also: The AISURU Botnet behind the massive 11.5 Tbps DDoS attack

Botnet DNS

When executed, the script launched a PowerShell routine to connect to a remote command-and-control server at 62.133.60.137 , a host with previous connections to Russian threat actors. Infoblox analysts identified that the underlying infrastructure is based on more than 13,000 compromised MikroTik routers that have been converted into open SOCKS4 servers . This extensive relay network not only increases email delivery volume but also obscures the true origin of the attacks, rendering traditional IP-based filtering ineffective.

Rather than exploiting a single vulnerability, the campaign exploits default or poorly secured configurations shipped with many MikroTik devices. The spam emails spoofed hundreds of legitimate domains by exploiting misconfigured SPF files. Domain owners had inadvertently—or through malicious tampering—configured their TXT files with the “ all ” directive, essentially allowing any mail server to send messages on their behalf. The result was a widespread bypass of DKIM, SPF , and DMARC checks , allowing malicious emails to bypass mail filters and reach corporate inboxes.

See also: L7 Botnet compromised 5.76 million devices for mass attacks

New Botnet Exploits DNS Misconfiguration

This botnet represents a fundamental shift in large-scale spam operations, combining network-level device compromise with DNS-level manipulation. Victims who opened the attached ZIP files activated a JavaScript file that deploys the loader script, demonstrating the seamless integration of multiple tactics to maximize infection rates and evade detection.

The malware infection chain starts with a JavaScript file inside a ZIP archive. When executed, the script writes and executes a PowerShell loader that connects to the C2 server to receive further payloads. Once the loader is active, the PowerShell script validates its execution context by querying Get-ExecutionPolicy. If the policy restricts script execution, the malware temporarily bypasses the restrictions using Set-ExecutionPolicy Bypass -Scope Process. It then establishes persistence by creating a scheduled task named “Updater” that runs upon user login.

See also: New NightshadeC2 botnet bypasses Windows Defender

New Botnet Exploits DNS Misconfiguration

This mechanism ensures that the payload remains active across reboots, while its network traffic is routed through the botnet's SOCKS4 proxies. The reliance on legitimate network services and legitimate DNS records blurs the line between innocent and malicious activity, posing a significant challenge for defenders and underscoring the urgent need for strict DNS configuration checks and enhanced router security.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS