ZeroHour
The Recordpublished ()ingested

Previously unidentified botnet targets unpatched TP

criticalVulnerability exploited in the wildimportance 60CVE-2023-1389

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-1389
Command Injection in TP-Link Archer AX21 Router Allows Remote Code Execution

CVE-2023-1389 is a command injection flaw (CWE-77) in TP-Link's Archer AX21 Wi-Fi 6 router that lets an attacker execute arbitrary operating-system commands on the device. It is triggered by sending crafted input to a remotely reachable service on the router, which passes attacker-controlled values to the device's shell without proper sanitization; the source data does not specify the vulnerable endpoint or exact affected firmware ranges. Successful exploitation yields remote code execution on the router, giving the attacker a foothold in the network where the router sits, from which they can pivot or abuse the device further. Any household or organization running an Archer AX21 router is affected, with the highest risk where the router's management interface is exposed to the internet. The flaw was added to CISA's KEV catalog on 2023-05-01, confirming exploitation in the wild; EPSS assigns a ~100% probability of exploitation within 30 days (top percentile), while no public proof-of-concept or ransomware association is documented in the source data.

Do: Update the Archer AX21 to the latest firmware available from TP-Link per the vendor's instructions (fixed firmware is published on the product's TP-Link support page). If updating is not immediately possible, disable WAN-side/remote management and restrict the router's web interface to the local network. Because exploitation is confirmed in the wild, also review exposed routers for signs of compromise, such as unexplained configuration changes or unexpected outbound traffic.

8.8100% KEV PoC ×2
  • TP-Link Archer AX21 (Archer AX-21) Wi-Fi 6 router
masslikely hundreds of thousands of routers deployed, with >100k plausibly internet-exposed
Full article738 words · extracted from therecord.media · click to collapse

A model of internet routers marketed to consumers and businesses is being targeted as part of an effort to grow a new botnet known as Ballista.

Researchers at cybersecurity firm Cato Networks said that during a recent investigation into router vulnerabilities, they discovered the botnet trying to infect TP-Link Archer routers. 

The hacker behind the malware, who they believe is based in Italy, has been exploiting a firmware vulnerability tracked as CVE-2023-1389 to allow the botnet to “spread itself automatically over the Internet” through the unpatched TP-Link devices. 

The Cybersecurity and Infrastructure Security Agency previously confirmed that CVE-2023-1389 is being exploited in the wild and ordered U.S. civilian agencies to patch the bug The documentation for the vulnerability and the patch emphasize the TP-Link model known as AX21 or AX1800. 

Ofek Vardi, security engineer at Cato Networks, said the researchers are moderately confident the hacker is based in Italy because of the IP address location of the command and control (C2) server and because of Italian-language strings found within the malware’s code.

“We suspect we caught this campaign in its early stages. We saw it evolving, as within a short timeframe, the threat actor changed the initial dropper to allow stealthier connections to the C2 server through the Tor network,” said Matan Mittelman, threat prevention team leader at Cato Networks.

“In this particular campaign, the malware allows the attacker to run arbitrary commands on compromised devices. This suggests the malware author may have bigger plans than a regular DDoS-for-hire botnet.”

Cato’s security team first identified this campaign on January 10 and saw several initial-access attempts over the court of a few weeks, with the most recent coming on February 17. 

Vardi noted that the malware was written in a way that would allow new capabilities to be added to future variants.

The researchers declined to comment on whether Italian or European authorities have been notified of the threat actor or the campaign. 

The researchers said they named the botnet Ballista as a reference to an ancient Roman weapon and said it has targeted manufacturing, healthcare, services and technology organizations in the U.S., Australia, China and Mexico.

A search on cybersecurity platform Censys found more than 6,000 vulnerable devices connected to the Internet, they said, adding that the botnet is still active. 

The malware fully takes over a device and reads configuration files on the system before setting up encrypted links and attempting to spread to other devices automatically by exploiting CVE-2023-1389.

Cato Networks found some evidence that the threat actor involved deploys tools to potentially steal data from targeted networks.The IP address tied to the threat actor is no longer responding, the researchers said, adding that they have found a new variant of the malware on the code repository GitHub. 

“This suggests an increase in the sophistication level of the campaign by the threat actor. While this malware sample shares similarities with other botnets, it remains distinct from widely used botnets such as Mirai and Mozi,” they said. 

Both Vardi and Mittelman said their findings illustrate why Internet of Things (IoT) devices like routers are constantly targeted by malicious hackers. They often have weak passwords and are typically not well-maintained. Most do not have automated security patching, leaving them vulnerable to bugs for months and potentially years.  

“Over the years, major IoT botnets like Mirai and Mozi have proven how easily routers can be exploited and threat actors have taken note,” Mittelman said. “Two key issues have played in their favor: the fact that users rarely deploy new firmware to their routers, coupled with the lack of regard for security by router vendors.”

U.S. officials in recent months have raised alarms about TP-Link routers specifically because they are repeatedly being exploited by Chinese hackers who have used them to breach telecommunications giants and critical infrastructure

For years, critical vulnerabilities in TP-Link routers have been abused by hackers who use them as cover for subsequent attacks or add them to powerful botnets that disrupt websites with bogus traffic. 

The Wall Street Journal reported in December that U.S. agencies have considered banning TP-Link devices.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ballista-botnet-tp-link-archer-routers