Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitybotnet-infrastructureembedded-device-vulnerabilityend-of-life-software

Mirai Botnet Exploits CVE-2025-29635 in End-of-Life D-Link DIR-823X Routers

Updated 2mo agoFirst seen Apr 22, 20265 sources

A Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection flaw in end-of-life D-Link DIR-823X routers, marking the first reported in-the-wild abuse of the vulnerability since its public disclosure and proof-of-concept release in 2025. Akamai said it began seeing attacks in early March 2026 through crafted POST requests to the /goform/set_prohibiting endpoint, where unsanitized input reaches system() and enables remote command execution on affected firmware versions 240126 and 240802. The activity targets discontinued devices unlikely to receive vendor fixes, increasing exposure for organizations still running the routers.

The attackers use the exploit to fetch and run a shell script that installs a Mirai variant dubbed tuxnokill, which retains common Mirai strings while using XOR obfuscation with key 0x30. Akamai linked the same actor to similar Mirai deployment patterns against TP-Link AX21 devices via CVE-2023-1389 and against ZTE ZXV10 H108L routers through another remote code execution flaw, underscoring continued botnet weaponization of older, publicly documented vulnerabilities. Security advisories recommend replacing unsupported D-Link hardware, restricting exposed administrative interfaces, and rapidly remediating known router flaws before they are folded into botnet operations.

Share:
Mirai Botnet Exploits CVE-2025-29635 in End-of-Life D-Link DIR-823X Routers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Apr 23, 20262mo ago

HKCERT issues alert on Mirai targeting end-of-life D-Link routers

HKCERT published a security bulletin warning that Mirai botnet activity was targeting end-of-life D-Link routers affected by CVE-2025-29635. The alert reflected broader defender notification following Akamai's findings.

Apr 21, 20262mo ago

Akamai publicly reports the Mirai campaign targeting D-Link routers

Akamai published research detailing the Mirai campaign targeting end-of-life D-Link DIR-823X routers via CVE-2025-29635 and warned that older, publicly documented flaws continue to be weaponized. The report urged organizations to replace retired devices and improve patching and exposure management.

Akamai links same actor to TP-Link and ZTE router exploitation

Akamai assessed that the same threat actor was also exploiting CVE-2023-1389 in TP-Link AX21 routers and a remote code execution flaw in ZTE ZXV10 H108L routers using a similar Mirai deployment pattern. This expanded the campaign beyond D-Link devices to multiple router brands.

Mar 1, 20264mo ago

Attackers deploy tuxnokill Mirai variant on compromised routers

The observed campaign downloaded and executed a shell script named dlink.sh to install a Mirai variant called tuxnokill on compromised D-Link routers. Reporting also identified infrastructure including payload host 88.214.20[.]14 and command-and-control server 64.89.161[.]130:44300.

Akamai observes Mirai exploitation of CVE-2025-29635

In early March 2026, Akamai SIRT detected in-the-wild exploitation of CVE-2025-29635 against D-Link DIR-823X routers, marking the first observed active abuse of the flaw. Attackers used crafted POST requests to the /goform/set_prohibiting endpoint to execute commands on vulnerable devices.

Mar 1, 20251y ago

Researchers disclose CVE-2025-29635 in D-Link DIR-823X routers

Researchers Wang Jinshuai and Zhao Jiangting publicly disclosed CVE-2025-29635, a command-injection flaw in D-Link DIR-823X routers, and proof-of-concept exploit details became available around the same time. The vulnerability later became the basis for Mirai botnet exploitation.

Nov 1, 20242y ago

D-Link DIR-823X routers reach end of life

The affected D-Link DIR-823X devices reached end-of-life status, reducing the likelihood of vendor security fixes for CVE-2025-29635. Subsequent reporting recommended replacing the unsupported routers or restricting exposed administration access.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Malware
2 linked
Organizations
7 linked
D-LinkTP-LinkZTE CorporationAkamai TechnologiesBleepingComputerGitHubSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.