• News/
  • https://www.bleepingcomputer.com/news/security/mikrotik-botnet-uses-misconfigured-spf-dns-records-to-spread-malware/

MikroTik botnet uses misconfigured SPF DNS records to spread malware

BleepingComputer
·
Bill Toulas
·
Published Jan 15, 2025
·
Updated

A newly discovered botnet of 13,000 MikroTik devices uses a misconfiguration in domain name server records to bypass email protections and deliver malware by spoofing roughly 20,000 web domains. The threat actor takes advantage of an improperly configured DNS record for the sender policy framework (SPF) used for listing all the servers authorized to send emails on behalf of a domain. According to DNS security company Infoblox, the malspam campaign was active in late November 2024. Some of the emails impersonated DHL Express shipping company and delivered fake freight invoices with a ZIP archive containing a malicious payload. Inside the ZIP attachment there was a JavaScript file that assembles and runs a PowerShell script. The script establishes a connection to the threat actor’s command and control (C2) server at a domain previously tied to Russian hackers. “The headers of the many spam emails revealed a vast array of domains and SMTP server IP addresses, and we realized we had uncovered a sprawling network of approximately 13,000 hijacked MikroTik devices, all part of a sizeable botnet,” explains Infoblox. Infoblox explains that SPF DNS records for about 20,000 domains were configured with the overly permissive "+all" option, which allows any server to send emails on behalf of those domains. "This essentially defeats the purpose of having an SPF record, because it opens the door for spoofing and unauthorized email sending" - Infoblox A safer choice is using the "-all" opti...

Read full article

Affected Software

2 affected components
Mikrotik devices
Mikrotik MikroTik RouterOS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly discovered botnet that exploits misconfigured SPF DNS records on MikroTik devices to deliver malware.

2

What security implications are discussed in the article?

The article highlights the risks of using misconfigured DNS records that can allow attackers to bypass email protections and spread malware.

3

What products or software are affected by the botnet?

The affected products include MikroTik devices and MikroTik RouterOS.

4

How are the attackers spreading malware through the botnet?

Attackers are using spoofed emails from approximately 20,000 web domains to deliver malware.

5

What is the scale of the MikroTik botnet mentioned in the article?

The MikroTik botnet reportedly comprises around 13,000 compromised devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203