Threat Advisory

Ballista Botnet Exploits TP-Link Archer Routers via RCE Vulnerability

Threat: Malware
Targeted Region: U.S., Australia & China
Targeted Sector: Technology & IT, Healthcare, Critical Infrastructure, Retail & E-Commerce
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Researchers have discovered global IoT botnet campaign has been actively exploiting TP-Link Archer routers, taking advantage of a remote code execution (RCE) vulnerability CVE-2023-1389. This botnet, named "Ballista," spreads autonomously across the Internet, gaining control of compromised routers and leveraging them for malicious activities such as denial-of-service (DoS) attacks and further exploitation. The campaign highlights ongoing security risks in IoT devices, particularly routers, which often remain unpatched and vulnerable due to inconsistent firmware updates and security measures by manufacturers.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Researchers have discovered global IoT botnet campaign has been actively exploiting TP-Link Archer routers, taking advantage of a remote code execution (RCE) vulnerability CVE-2023-1389. This botnet, named "Ballista," spreads autonomously across the Internet, gaining control of compromised routers and leveraging them for malicious activities such as denial-of-service (DoS) attacks and further exploitation. The campaign highlights ongoing security risks in IoT devices, particularly routers, which often remain unpatched and vulnerable due to inconsistent firmware updates and security measures by manufacturers.[emaillocker id="1283"]

The Ballista botnet propagates by exploiting CVE-2023-1389, initially delivering a malware dropper via a bash script that downloads and executes the payload. The malware then removes its traces from the system to evade detection and establishes an encrypted command and control (C2) channel. Through this channel, attackers can execute shell commands, conduct DoS attacks, and attempt to access sensitive system files. The botnet also incorporates modular functionality, allowing for the execution of different attack types, including TCP flood attacks. Notably, as the campaign evolved, the botnet switched to using Tor domains instead of hard-coded IP addresses, increasing its stealth capabilities. Analysis suggests a link to an Italian-based threat actor due to the presence of Italian strings in the malware and associated IP addresses.

Ballista presents a significant threat to organizations across various industries, including manufacturing, healthcare, technology, and services, with confirmed targets in multiple countries. The botnet remains active, with thousands of vulnerable TP-Link Archer routers still exposed to potential compromise due to CVE-2023-1389. Its ability to spread autonomously and execute various attack vectors underscores the need for immediate patching of affected devices, strict network monitoring, and robust security measures. Given the botnet’s evolution and use of encryption to conceal communications, organizations must adopt proactive defenses, such as intrusion prevention systems, IoT security policies, and behavioral threat detection, to mitigate the risk.

 

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
Defense Evasion T1222 File and Directory Permissions Modification
T1070 Indicator Removal
T1027 Obfuscated Files or Information
Credential Access T1555 Credentials from Password Stores
Discovery T1083 File and Directory Discovery
T1201 Password Policy Discovery
T1057 Process Discovery
T1082 System Information Discovery
T1016 System Network Configuration Discovery
Collection T1005 Data from Local System
Command and Control T1095 Non-Application Layer Protocol
T1571 Non-Standard Port
T1105 Ingress Tool Transfer
T1071 Application Layer Protocol
T1090 Proxy
T1665 Hide Infrastructure
Exfiltration T1537 Transfer Data to Cloud Account

 

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2025/03/ballista-botnet-exploits-unpatched-tp.html

[/emaillocker]
crossmenu