Affected Systems
Internet-facing Linux-based edge devices including routers (NETGEAR, Tenda, D-Link, TP-Link, Zyxel), IP cameras (Hikvision), enterprise appliances (Alcatel OmniPCX, Mitsubishi ME-RTU, Telesquare SDT-CW3B1/TLR-2005KSH), and servers running vulnerable Atlassian Confluence, WSO2, PHP, and Kubernetes instances. Active since July 2026.
Exploitation Status
Active exploitation in the wild since July 2026. Botnet weaponizes 18 known CVEs (ranging from 2007 to 2025) to compromise devices. Loader infrastructure observed at 91.92.40[.]118. C2 communications use port 443 to blend with HTTPS traffic.
Business Impact
Compromised devices become SOCKS5 proxies enabling threat actors to anonymize malicious traffic, bypass geographic restrictions, and access internal networks. Infected hosts also support DDoS attacks, SSH brute-forcing, credential theft (HTTP Basic Auth and cookies), and lateral movement. Organizations may unknowingly provide proxy infrastructure for criminal operations or face bandwidth abuse and reputational damage.
Urgency
🟠 Within 24 hours
Recommended Actions
- Patch all internet-facing edge devices against the 18 exploited CVEs, prioritizing CVE-2024-4577 (PHP), CVE-2023-1389 (TP-Link), CVE-2022-26134 (Atlassian Confluence), CVE-2021-36260 (Hikvision), and 2025-era D-Link flaws (CVE-2025-10123, CVE-2025-55583)
- Block outbound connections to 91.92.40[.]118 and monitor for unusual outbound traffic on port 443 from IoT/edge devices that do not normally initiate HTTPS sessions
- Audit edge devices (routers, IP cameras, firewalls) for unexpected processes, cleared Bash history, persistence mechanisms, and SOCKS5 proxy listeners
- Implement network segmentation to isolate IoT and edge devices from critical internal networks and enforce egress filtering to prevent proxy abuse
- Monitor for SSH brute-force activity originating from internal edge devices and inspect HTTP traffic for credential interception (Basic Auth, Cookie headers)
