A new Mirai-based botnet malware named ‘ShadowV2’ has been observed targeting IoT devices from D-Link, TP-Link, and other vendors with exploits for known vulnerabilities. Fortinet’s FortiGuard Labs researchers spotted the activity during the major AWS outage in October. Although the two incidents are not connected, the botnet was active only for the duration of the outage, which may indicate that it was a test run. ShadowV2 spread by leveraging at least eight vulnerabilities in multiple IoT products: Among these flaws, CVE-2024-10914 is a known-to-be-exploited command injection flaw impacting EoL D-Link devices, which the vendor announced that it would not fix. Regarding CVE-2024-10915, for which there’s a NetSecFish report from November 2024, BleepingComputer initially did not find the vendor's advisory for the flaw. After reaching out to the company, we received confirmation that the issue would not be fixed for the impacted models. D-Link updated an older bulletin to add the particular CVE-ID and published a new one referring to the ShadowV2 campaign, to warn users that end-of-life or end-of-support devices are no longer under development and will not receive firmware updates. CVE-2024-53375, which was also presented in detail in November 2024, was reportedly fixed via a beta firmware update. According to FortiGuard Labs researchers, the ShadowV2 attacks originated from 198[.]199[.]72[.]27, and targeted routers, NAS devices, and DVRs across seven sectors, including govern...
New ShadowV2 botnet malware used AWS outage as a test opportunity
BleepingComputer
·Bill Toulas
·Published Nov 26, 2025
·Updated
Affected Software
2 affected components
D-Link IoT devices
TP-Link IoT devices
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of a new Mirai-based botnet malware called 'ShadowV2' that targets IoT devices.
2
What security implications are discussed in the article?
The article highlights the risks associated with unsecured IoT devices being exploited by the ShadowV2 botnet.
3
What products or software are affected by the ShadowV2 botnet?
The affected products include IoT devices from D-Link and TP-Link.
4
How was ShadowV2 utilized during the AWS outage?
ShadowV2 was observed taking advantage of the AWS outage to test its malicious capabilities.
5
Who identified the ShadowV2 botnet malware activity?
The activity of the ShadowV2 botnet was spotted by researchers from Fortinet’s FortiGuard Labs.