ShadowV2 Mirai-based IoT botnet activity
Malware Activity
Summary
Hide ▲
Show ▼
The Mirai-based botnet ShadowV2 was observed targeting IoT devices from D-Link, TP-Link, and other vendors, creating DDoS risk across exposed systems. Researchers linked the activity to known vulnerabilities, a downloader script, and command-driven attacks over UDP, TCP, and HTTP. The botnet was seen during the October AWS outage window and appears to have been active only briefly, which may indicate a test run.
Related Happenings
C0XMO Gafgyt botnet activity on DD-WRT routers
Malware Activity
H score19
First: 07.06.2026 17:17
Last: 07.06.2026 17:17
Sources 1
About this happening:
The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits...
C0XMO Gafgyt botnet activity on DD-WRT routers
Malware ActivityAbout this happening: The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits...
Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign
Campaign
H score38
First: 22.04.2026 23:04
Last: 22.04.2026 23:04
Sources 1
About this happening:
The Mirai-based malware campaign is actively exploiting CVE-2025-29635 against D-Link DIR-823X routers, turning vulnerable devices into botnet nodes. The activity matt...
Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign
CampaignAbout this happening: The Mirai-based malware campaign is actively exploiting CVE-2025-29635 against D-Link DIR-823X routers, turning vulnerable devices into botnet nodes. The activity matt...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
Vulnerability
H score1
First: 20.04.2026 16:01
Last: 20.04.2026 16:01
Sources 1
About this happening:
The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
VulnerabilityAbout this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
Nexcorium Mirai botnet activity on TBK DVR devices
Malware Activity
H score27
First: 18.04.2026 09:01
Last: 18.04.2026 09:01
Sources 1
About this happening:
Nexcorium, a Mirai variant, is now being deployed against TBK DVR-4104 and DVR-4216 devices by exploiting CVE-2024-3721, turning compromised IoT hardware into...
Nexcorium Mirai botnet activity on TBK DVR devices
Malware ActivityAbout this happening: Nexcorium, a Mirai variant, is now being deployed against TBK DVR-4104 and DVR-4216 devices by exploiting CVE-2024-3721, turning compromised IoT hardware into...
AVRecon malware for Linux powering SocksEscort proxy network
Malware Activity
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
AVRecon malware for Linux powering SocksEscort proxy network
Malware ActivityAbout this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
Timeline
-
27.11.2025 00:24 2 articles · 7mo ago
ShadowV2 observed targeting IoT devices during the October AWS outage
Initial DisclosureFortiGuard Labs researchers observed the Mirai-based botnet ShadowV2 targeting D-Link, TP-Link, and other IoT devices during the major AWS outage in October, and the activity was active only for the outage window, suggesting a possible test run. The botnet spread by leveraging at least eight known vulnerabilities across DD-WRT, D-Link, DigiEver, TBK, and TP-Link devices, originated from 198[.]199[.]72[.]27, and used a downloader script, binary.sh, to fetch payloads from 81[.]88[.]18[.]108. ShadowV2 identifies itself as "ShadowV2 Build v1.0.0 IoT version," supports DDoS attacks over UDP, TCP, and HTTP, and Fortinet shared IoCs to help defenders identify exposed devices, including end-of-life D-Link models that will not receive firmware fixes and TP-Link systems associated with CVE-2024-53375.
Show sources
- New ShadowV2 botnet malware used AWS outage as a test opportunity — www.bleepingcomputer.com — 27.11.2025 00:24
- New ShadowV2 botnet malware used AWS outage as a test opportunity — www.bleepingcomputer.com — 27.11.2025 00:24