EXECUTIVE SUMMARY:
Researchers have discovered global IoT botnet campaign has been actively exploiting TP-Link Archer routers, taking advantage of a remote code execution (RCE) vulnerability CVE-2023-1389. This botnet, named "Ballista," spreads autonomously across the Internet, gaining control of compromised routers and leveraging them for malicious activities such as denial-of-service (DoS) attacks and further exploitation. The campaign highlights ongoing security risks in IoT devices, particularly routers, which often remain unpatched and vulnerable due to inconsistent firmware updates and security measures by manufacturers.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have discovered global IoT botnet campaign has been actively exploiting TP-Link Archer routers, taking advantage of a remote code execution (RCE) vulnerability CVE-2023-1389. This botnet, named "Ballista," spreads autonomously across the Internet, gaining control of compromised routers and leveraging them for malicious activities such as denial-of-service (DoS) attacks and further exploitation. The campaign highlights ongoing security risks in IoT devices, particularly routers, which often remain unpatched and vulnerable due to inconsistent firmware updates and security measures by manufacturers.[emaillocker id="1283"]
The Ballista botnet propagates by exploiting CVE-2023-1389, initially delivering a malware dropper via a bash script that downloads and executes the payload. The malware then removes its traces from the system to evade detection and establishes an encrypted command and control (C2) channel. Through this channel, attackers can execute shell commands, conduct DoS attacks, and attempt to access sensitive system files. The botnet also incorporates modular functionality, allowing for the execution of different attack types, including TCP flood attacks. Notably, as the campaign evolved, the botnet switched to using Tor domains instead of hard-coded IP addresses, increasing its stealth capabilities. Analysis suggests a link to an Italian-based threat actor due to the presence of Italian strings in the malware and associated IP addresses.
Ballista presents a significant threat to organizations across various industries, including manufacturing, healthcare, technology, and services, with confirmed targets in multiple countries. The botnet remains active, with thousands of vulnerable TP-Link Archer routers still exposed to potential compromise due to CVE-2023-1389. Its ability to spread autonomously and execute various attack vectors underscores the need for immediate patching of affected devices, strict network monitoring, and robust security measures. Given the botnet’s evolution and use of encryption to conceal communications, organizations must adopt proactive defenses, such as intrusion prevention systems, IoT security policies, and behavioral threat detection, to mitigate the risk.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| Defense Evasion | T1222 | File and Directory Permissions Modification |
| T1070 | Indicator Removal | |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1555 | Credentials from Password Stores |
| Discovery | T1083 | File and Directory Discovery |
| T1201 | Password Policy Discovery | |
| T1057 | Process Discovery | |
| T1082 | System Information Discovery | |
| T1016 | System Network Configuration Discovery | |
| Collection | T1005 | Data from Local System |
| Command and Control | T1095 | Non-Application Layer Protocol |
| T1571 | Non-Standard Port | |
| T1105 | Ingress Tool Transfer | |
| T1071 | Application Layer Protocol | |
| T1090 | Proxy | |
| T1665 | Hide Infrastructure | |
| Exfiltration | T1537 | Transfer Data to Cloud Account |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2025/03/ballista-botnet-exploits-unpatched-tp.html