A Mirai-based botnet named ShadowV2 emerged during last October's widespread AWS outage, infecting IoT devices across industries and continents, likely serving as a "test run" for future attacks, according to Fortinet's FortiGuard Labs. After infecting vulnerable gear to form a zombie army of IoT devices, the ShadowV2 Mirai variant allows an attacker to remotely control the network of equipment and perform large-scale attacks, including distributed-denial-of-service (DDoS) traffic-flooding events. Luckily, the malware only remained active during the day-long outage, which also knocked major websites offline for hours. During that time, it propagated via several vulnerabilities affecting devices from multiple vendors, including DD-WRT (CVE-2009-2765), D-Link (CVE-2020-25506, CVE-2022-37055, CVE-2024-10914, CVE-2024-10915), DigiEver (CVE-2023-52163), TBK (CVE-2024-3721), and TP-Link (CVE-2024-53375), antivirus analyst Vincent Li said in a Wednesday blog post. While ShadowV2, a cloud-native botnet, previously targeted AWS EC2 instances in September campaigns, the more recent bot-building effort affected multiple sectors, including technology, retail and hospitality, manufacturing, managed security services providers, government, telecommunication and carrier services, and education. And it hit 28 countries: Canada, US, Mexico, Brazil, Bolivia, Chile, UK, Netherlands, Belgium, France, Czechia, Austria, Italy, Croatia, Greece, Morocco, Egypt, South Africa, Turkey, Saudi Arabia, R...
Botnet takes advantage of AWS outage to smack 28 countries
The Register
·Jessica Lyons
·Published Nov 26, 2025
·Updated
Affected Software
5 affected components
DD-WRT DD-WRT
D-Link D-Link
Digiever DigiEver
TBK TBK
TP-Link TP-LINK
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the emergence of a Mirai-based botnet named ShadowV2 that exploited an AWS outage to attack IoT devices globally.
2
What security implications are discussed in the article?
The article highlights the potential for ShadowV2 to serve as a test run for future, more sophisticated attacks on IoT infrastructure.
3
What products or software are affected by the ShadowV2 botnet?
The ShadowV2 botnet has infected various IoT devices, particularly those running firmware from DD-WRT, D-Link, DigiEver, TBK, and TP-Link.
4
Which industries are primarily impacted by this botnet attack?
The botnet targets IoT devices across multiple industries, indicating a wide range of vulnerability.
5
How does the botnet exploit AWS outages?
The botnet exploits the chaos during AWS outages to increase the likelihood of successfully infecting devices without immediate detection.