• News/
  • https://www.bleepingcomputer.com/news/security/new-shadowv2-botnet-malware-used-aws-outage-as-a-test-opportunity/

New ShadowV2 botnet malware used AWS outage as a test opportunity

BleepingComputer
·
Bill Toulas
·
Published Nov 26, 2025
·
Updated

A new Mirai-based botnet malware named ‘ShadowV2’ has been observed targeting IoT devices from D-Link, TP-Link, and other vendors with exploits for known vulnerabilities. Fortinet’s FortiGuard Labs researchers spotted the activity during the major AWS outage in October. Although the two incidents are not connected, the botnet was active only for the duration of the outage, which may indicate that it was a test run. ShadowV2 spread by leveraging at least eight vulnerabilities in multiple IoT products: Among these flaws, CVE-2024-10914 is a known-to-be-exploited command injection flaw impacting EoL D-Link devices, which the vendor announced that it would not fix. Regarding CVE-2024-10915, for which there’s a NetSecFish report from November 2024, BleepingComputer initially did not find the vendor's advisory for the flaw. After reaching out to the company, we received confirmation that the issue would not be fixed for the impacted models. D-Link updated an older bulletin to add the particular CVE-ID and published a new one referring to the ShadowV2 campaign, to warn users that end-of-life or end-of-support devices are no longer under development and will not receive firmware updates. CVE-2024-53375, which was also presented in detail in November 2024, was reportedly fixed via a beta firmware update. According to FortiGuard Labs researchers, the ShadowV2 attacks originated from 198[.]199[.]72[.]27, and targeted routers, NAS devices, and DVRs across seven sectors, including govern...

Read full article

Affected Software

2 affected components
D-Link IoT devices
TP-Link IoT devices
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of a new Mirai-based botnet malware called 'ShadowV2' that targets IoT devices.

2

What security implications are discussed in the article?

The article highlights the risks associated with unsecured IoT devices being exploited by the ShadowV2 botnet.

3

What products or software are affected by the ShadowV2 botnet?

The affected products include IoT devices from D-Link and TP-Link.

4

How was ShadowV2 utilized during the AWS outage?

ShadowV2 was observed taking advantage of the AWS outage to test its malicious capabilities.

5

Who identified the ShadowV2 botnet malware activity?

The activity of the ShadowV2 botnet was spotted by researchers from Fortinet’s FortiGuard Labs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203