New ShadowV2 botnet malware used AWS outage as a test opportunity
With exploits for known vulnerabilities, a new Mirai-based botnet virus known as "ShadowV2" has been seen to attack IoT devices from D-Link, TP-Link, and other companies.
Researchers at Fortinet's FortiGuard Labs saw the activity during the significant October AWS outage. The botnet was only active during the outage, which may suggest that it was a test run even though the two instances are unrelated.
ShadowV2 propagated via taking use of at least eight flaws in various Internet of Things products:
DD-WRT (CVE-2009-2765)
D-Link (CVE-2020-25506, CVE-2022-37055, CVE-2024-10914, CVE-2024-10915)
DigiEver (CVE-2023-52163)
TBK (CVE-2024-3721)
TP-Link (CVE-2024-53375)
Among these vulnerabilities, the vendor declared that it would not address CVE-2024-10914, a known-to-b...

