Live
eineurope/
Home/Global/Topic · Mirai botnet exploits D-Link router flaw
Global5d ago

Mirai botnet exploits D-Link router flaw

The Mirai botnet is actively exploiting a critical vulnerability in end-of-life D-Link routers to deploy DDoS malware.

Sources
1 verified
Location
Updated
Thursday, 23 April 2026 at 05:57 UTC
No media · text-only dispatch
Synthesis · 1 sources
Akamai SIRT has detected the first in-the-wild exploitation of CVE-2025-29635, a command-injection vulnerability in D-Link DIR-823X routers. The campaign deploys a Mirai variant called "tuxnokill" by sending malicious POST requests to vulnerable endpoints, downloading shell scripts, and installing DDoS-capable malware. The flaw was disclosed in February 2025, but active exploitation only began in March 2026 according to Akamai's analysis. Affected devices reached end-of-life in November 2024, making security patches unlikely, and the same threat actor is also targeting TP-Link and ZTE routers with similar tactics.
e/eineurope · topic · T-04968