<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Exploit Forums - Botnets]]></title>
		<link>https://exploitforums.net/</link>
		<description><![CDATA[Exploit Forums - https://exploitforums.net]]></description>
		<pubDate>Thu, 28 May 2026 01:22:38 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Botnets Exploit Wazuh Vulnerability for Mirai-Based Attacks]]></title>
			<link>https://exploitforums.net/showthread.php?tid=12</link>
			<pubDate>Tue, 10 Jun 2025 13:16:25 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exploitforums.net/member.php?action=profile&uid=2">Preeminence</a>]]></dc:creator>
			<guid isPermaLink="false">https://exploitforums.net/showthread.php?tid=12</guid>
			<description><![CDATA[Threat actors are actively exploiting CVE-2025-24016, a critical remote code execution vulnerability in Wazuh servers, to deploy two distinct Mirai-based botnets for distributed denial-of-service (DDoS) attacks. Akamai first identified the malicious activity in late March 2025, shortly after the public disclosure of the vulnerability and a proof-of-concept (PoC) exploit. The flaw, affecting versions 4.4.0 and later, was patched in February 2025 with version 4.9.1, but attackers continue to exploit unpatched systems.<br />
<br />
The first botnet delivers the LZRD Mirai variant, previously observed targeting IoT devices. Infrastructure analysis uncovered additional Mirai variants, including "neon" and "vision," along with exploits targeting Hadoop YARN and various router vulnerabilities.<br />
<br />
The second botnet deploys the Resbot variant and appears to have connections to Italian-language domains, suggesting a campaign possibly targeting Italian-speaking users. It leverages multiple exploits against Huawei, Realtek, and ZyXEL routers.<br />
<br />
Researchers note that Mirai propagation remains persistent, with attackers frequently repurposing older exploits and incorporating newly disclosed vulnerabilities, including CVE-2024-3721.<br />
Globally, botnet activity continues to rise, especially in the APAC region and among IoT devices, contributing to an increase in sophisticated cyberattacks. Additionally, the FBI has warned about the BADBOX 2.0 botnet, which has infected millions of devices to create proxy networks for cybercriminals.<br />
<br />
Source: <a href="https://thehackernews.com/2025/06/botnet-wazuh-server-vulnerability.html" target="_blank" rel="noopener" class="mycode_url">https://thehackernews.com/2025/06/botnet...ility.html</a>]]></description>
			<content:encoded><![CDATA[Threat actors are actively exploiting CVE-2025-24016, a critical remote code execution vulnerability in Wazuh servers, to deploy two distinct Mirai-based botnets for distributed denial-of-service (DDoS) attacks. Akamai first identified the malicious activity in late March 2025, shortly after the public disclosure of the vulnerability and a proof-of-concept (PoC) exploit. The flaw, affecting versions 4.4.0 and later, was patched in February 2025 with version 4.9.1, but attackers continue to exploit unpatched systems.<br />
<br />
The first botnet delivers the LZRD Mirai variant, previously observed targeting IoT devices. Infrastructure analysis uncovered additional Mirai variants, including "neon" and "vision," along with exploits targeting Hadoop YARN and various router vulnerabilities.<br />
<br />
The second botnet deploys the Resbot variant and appears to have connections to Italian-language domains, suggesting a campaign possibly targeting Italian-speaking users. It leverages multiple exploits against Huawei, Realtek, and ZyXEL routers.<br />
<br />
Researchers note that Mirai propagation remains persistent, with attackers frequently repurposing older exploits and incorporating newly disclosed vulnerabilities, including CVE-2024-3721.<br />
Globally, botnet activity continues to rise, especially in the APAC region and among IoT devices, contributing to an increase in sophisticated cyberattacks. Additionally, the FBI has warned about the BADBOX 2.0 botnet, which has infected millions of devices to create proxy networks for cybercriminals.<br />
<br />
Source: <a href="https://thehackernews.com/2025/06/botnet-wazuh-server-vulnerability.html" target="_blank" rel="noopener" class="mycode_url">https://thehackernews.com/2025/06/botnet...ility.html</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[The Rise and Fall of IoT Botnets]]></title>
			<link>https://exploitforums.net/showthread.php?tid=5</link>
			<pubDate>Thu, 05 Jun 2025 20:12:54 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exploitforums.net/member.php?action=profile&uid=1">Adamantium</a>]]></dc:creator>
			<guid isPermaLink="false">https://exploitforums.net/showthread.php?tid=5</guid>
			<description><![CDATA[From 2013 to 2020, the internet experienced what could be called the Golden Age of IoT botnet chaos. Botnets like Mirai, Bashlite, and Aidra took advantage of the explosion in poorly secured Internet of Things (IoT) devices—exploiting default credentials, unpatched firmware, and careless user behavior to build massive networks of hijacked routers, IP cameras, DVRs, and even smart fridges. These compromised devices were turned into digital weapons, capable of launching large-scale attacks that reshaped the landscape of cyberwarfare. One of the most infamous examples was Mirai’s 2016 attack on DNS provider Dyn, which brought down major platforms like Twitter, Netflix, and Reddit with a 1.2 Tbps distributed denial-of-service (DDoS) assault. This incident served as a wake-up call to the world: IoT security was dangerously inadequate, and cybercriminals were profiting from it. At its peak, Mirai infected over 600,000 devices, exposing how vulnerable the backbone of the internet truly was.<br />
<br />
The dominance of IoT botnets during this period was fueled by several factors. First, the low-hanging fruit of unsecured devices made them easy targets. Default usernames and passwords like “admin:admin” and open Telnet ports meant that attackers could compromise devices simply by scanning IP ranges. Second, the sheer scale of IoT proliferation played a critical role. By 2020, there were over 20 billion IoT devices connected to the internet, many of which were never patched or updated—giving botnets a virtually unlimited pool of potential recruits. Third, profit became a major motivator. Botnets evolved into a service industry, with offerings like “Mirai as a Service” allowing even unskilled users to launch DDoS attacks for as little as &#36;19.99 a month.<br />
<br />
However, the era of unchecked IoT botnet growth eventually came to an end due to a combination of law enforcement, vigilante malware, and improved security practices. Authorities arrested the original creators of Mirai in 2017, although the botnet's source code had already been made public, leading to numerous variants. Meanwhile, vigilante efforts emerged in the form of malware like Hajime and BrickerBot, which actively sought to disable infected devices to prevent them from being used in more harmful attacks. Additionally, ISPs and manufacturers began to implement mandatory firmware updates and improve default security settings, while regulatory pressure further encouraged better cybersecurity practices across the industry.<br />
<br />
Although the original wave of IoT botnets has subsided, the threat has not disappeared—it has evolved. Modern botnets like Mozi and DarkNexus now target enterprise-level hardware and hide their command-and-control infrastructure behind peer-to-peer networks, making them harder to detect and shut down. While the chaotic, wide-open days of IoT exploitation may be over, today’s threats are stealthier and more sophisticated. <br />
<br />
<span style="font-weight: bold;" class="mycode_b">The question remains:</span> did IoT botnets truly peak in 2016, or are we simply entering a new, smarter phase of cyber warfare?]]></description>
			<content:encoded><![CDATA[From 2013 to 2020, the internet experienced what could be called the Golden Age of IoT botnet chaos. Botnets like Mirai, Bashlite, and Aidra took advantage of the explosion in poorly secured Internet of Things (IoT) devices—exploiting default credentials, unpatched firmware, and careless user behavior to build massive networks of hijacked routers, IP cameras, DVRs, and even smart fridges. These compromised devices were turned into digital weapons, capable of launching large-scale attacks that reshaped the landscape of cyberwarfare. One of the most infamous examples was Mirai’s 2016 attack on DNS provider Dyn, which brought down major platforms like Twitter, Netflix, and Reddit with a 1.2 Tbps distributed denial-of-service (DDoS) assault. This incident served as a wake-up call to the world: IoT security was dangerously inadequate, and cybercriminals were profiting from it. At its peak, Mirai infected over 600,000 devices, exposing how vulnerable the backbone of the internet truly was.<br />
<br />
The dominance of IoT botnets during this period was fueled by several factors. First, the low-hanging fruit of unsecured devices made them easy targets. Default usernames and passwords like “admin:admin” and open Telnet ports meant that attackers could compromise devices simply by scanning IP ranges. Second, the sheer scale of IoT proliferation played a critical role. By 2020, there were over 20 billion IoT devices connected to the internet, many of which were never patched or updated—giving botnets a virtually unlimited pool of potential recruits. Third, profit became a major motivator. Botnets evolved into a service industry, with offerings like “Mirai as a Service” allowing even unskilled users to launch DDoS attacks for as little as &#36;19.99 a month.<br />
<br />
However, the era of unchecked IoT botnet growth eventually came to an end due to a combination of law enforcement, vigilante malware, and improved security practices. Authorities arrested the original creators of Mirai in 2017, although the botnet's source code had already been made public, leading to numerous variants. Meanwhile, vigilante efforts emerged in the form of malware like Hajime and BrickerBot, which actively sought to disable infected devices to prevent them from being used in more harmful attacks. Additionally, ISPs and manufacturers began to implement mandatory firmware updates and improve default security settings, while regulatory pressure further encouraged better cybersecurity practices across the industry.<br />
<br />
Although the original wave of IoT botnets has subsided, the threat has not disappeared—it has evolved. Modern botnets like Mozi and DarkNexus now target enterprise-level hardware and hide their command-and-control infrastructure behind peer-to-peer networks, making them harder to detect and shut down. While the chaotic, wide-open days of IoT exploitation may be over, today’s threats are stealthier and more sophisticated. <br />
<br />
<span style="font-weight: bold;" class="mycode_b">The question remains:</span> did IoT botnets truly peak in 2016, or are we simply entering a new, smarter phase of cyber warfare?]]></content:encoded>
		</item>
	</channel>
</rss>