• News/
  • https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/

Botnet takes advantage of AWS outage to smack 28 countries

The Register
·
Jessica Lyons
·
Published Nov 26, 2025
·
Updated

A Mirai-based botnet named ShadowV2 emerged during last October's widespread AWS outage, infecting IoT devices across industries and continents, likely serving as a "test run" for future attacks, according to Fortinet's FortiGuard Labs. After infecting vulnerable gear to form a zombie army of IoT devices, the ShadowV2 Mirai variant allows an attacker to remotely control the network of equipment and perform large-scale attacks, including distributed-denial-of-service (DDoS) traffic-flooding events. Luckily, the malware only remained active during the day-long outage, which also knocked major websites offline for hours. During that time, it propagated via several vulnerabilities affecting devices from multiple vendors, including DD-WRT (CVE-2009-2765), D-Link (CVE-2020-25506, CVE-2022-37055, CVE-2024-10914, CVE-2024-10915), DigiEver (CVE-2023-52163), TBK (CVE-2024-3721), and TP-Link (CVE-2024-53375), antivirus analyst Vincent Li said in a Wednesday blog post. While ShadowV2, a cloud-native botnet, previously targeted AWS EC2 instances in September campaigns, the more recent bot-building effort affected multiple sectors, including technology, retail and hospitality, manufacturing, managed security services providers,  government, telecommunication and carrier services, and education. And it hit 28 countries: Canada, US, Mexico, Brazil, Bolivia, Chile, UK, Netherlands, Belgium, France, Czechia, Austria, Italy, Croatia, Greece, Morocco, Egypt, South Africa, Turkey, Saudi Arabia, R...

Read full article

Affected Software

5 affected components
DD-WRT DD-WRT
D-Link D-Link
Digiever DigiEver
TBK TBK
TP-Link TP-LINK
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the emergence of a Mirai-based botnet named ShadowV2 that exploited an AWS outage to attack IoT devices globally.

2

What security implications are discussed in the article?

The article highlights the potential for ShadowV2 to serve as a test run for future, more sophisticated attacks on IoT infrastructure.

3

What products or software are affected by the ShadowV2 botnet?

The ShadowV2 botnet has infected various IoT devices, particularly those running firmware from DD-WRT, D-Link, DigiEver, TBK, and TP-Link.

4

Which industries are primarily impacted by this botnet attack?

The botnet targets IoT devices across multiple industries, indicating a wide range of vulnerability.

5

How does the botnet exploit AWS outages?

The botnet exploits the chaos during AWS outages to increase the likelihood of successfully infecting devices without immediate detection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203