Tech »  Topic »  New Ballista IoT Botnet Linked to Italian Threat Actor

New Ballista IoT Botnet Linked to Italian Threat Actor


Cato Networks has discovered a new IoT botnet that targets TP-Link Archer routers through the exploitation of a vulnerability discovered two years ago.

The botnet has been linked with moderate confidence — based on an IP address and strings found in malware binaries — to an unnamed Italian threat actor, which is why Cato has called it Ballista, the name of a missile launcher used by the Roman empire.

Cato first saw Ballista on January 10 and the most recent activity was observed in mid-February, but the security firm believes the botnet is still active.

Ballista has targeted organizations in the US, Australia, China and Mexico, including in the manufacturing, healthcare, services, and technology sectors.

The botnet targets TP-Link Archer routers by exploiting a vulnerability tracked as CVE-2023-1389. This flaw was discovered at a Pwn2Own hacker competition in late 2022 and its exploitation was first reported in May 2023. Later it was ...


Copyright of this story solely belongs to securityweek . To see the full text click HERE