Executive Summary
In early 2024, security researchers observed an escalating wave of activity from botnets such as Mirai, leveraging vulnerabilities and misconfigurations across cloud environments and Internet-exposed assets. Attackers targeted PHP servers, IoT devices, and cloud gateways, exploiting both known flaws and weak security controls. Once compromised, these assets were co-opted into large-scale botnets used for distributed denial-of-service (DDoS) attacks, cryptomining, and lateral movement into business networks. The campaign underscored gaps in east-west traffic visibility, workload segmentation, and egress filtering, significantly increasing operational and reputational risk for enterprises.
This incident is part of a growing trend where botnets and automated threat actors shift focus to cloud and hybrid environments, capitalizing on common misconfigurations. Organizations face mounting pressure to modernize defenses, as attackers rapidly adapt to evolving architectures and compliance expectations.
Why This Matters Now
Botnet operators are adapting to target cloud and hybrid environments, exploiting routine misconfigurations and software flaws at scale. With cloud adoption surging and asset sprawl accelerating, these automated campaigns pose a heightened risk of downtime, data loss, and regulatory noncompliance, making robust east-west controls and zero trust practices more urgent than ever.
Attack Path Analysis
The attack began with botnet operators exploiting exposed or misconfigured cloud-based assets, such as PHP servers or IoT gateways. After establishing access, the adversary leveraged privilege escalation techniques to deepen their foothold within the cloud environment. Lateral movement ensued as attackers traversed internal east-west pathways to compromise additional workloads and services. The botnet established persistent command and control (C2) channels to coordinate and expand the attack infrastructure. Adversaries then attempted exfiltration of data or used cloud resources to propagate further attacks. Lastly, operational impact was delivered as compromised cloud assets were weaponized for attacks, potentially causing service disruption or being enrolled into larger botnet campaigns.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited public-facing cloud workloads and misconfigured assets (such as web servers and IoT gateways) to gain initial access.
Related CVEs
CVE-2024-3721
CVSS 9.8A command injection vulnerability in TBK DVR-4104 and DVR-4216 devices allows unauthenticated remote attackers to execute arbitrary commands via unsanitized parameters in HTTP requests.
Affected Products:
TBK DVR-4104 – All versions
TBK DVR-4216 – All versions
Exploit Status:
exploited in the wildCVE-2022-22947
CVSS 9.8A remote code execution vulnerability in Spring Cloud Gateway allows unauthenticated attackers to execute arbitrary code via a maliciously crafted request to the /actuator/refresh endpoint.
Affected Products:
VMware Spring Cloud Gateway – < 3.1.1, < 3.0.7
Exploit Status:
exploited in the wildCVE-2024-6047
CVSS 9.8A command injection vulnerability in GeoVision IoT devices allows unauthenticated remote attackers to execute arbitrary system commands via the /DateSetting.cgi endpoint.
Affected Products:
GeoVision IoT Devices – End-of-Life models
Exploit Status:
exploited in the wildCVE-2024-11120
CVSS 9.8A command injection vulnerability in GeoVision IoT devices allows unauthenticated remote attackers to execute arbitrary system commands via the /DateSetting.cgi endpoint.
Affected Products:
GeoVision IoT Devices – End-of-Life models
Exploit Status:
exploited in the wildCVE-2025-24016
CVSS 9.9An unsafe deserialization vulnerability in Wazuh servers allows remote code execution by unauthenticated attackers via crafted API requests.
Affected Products:
Wazuh Wazuh Server – 4.4.0 to 4.9.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Network Service Scanning
Create Account
Command and Scripting Interpreter
Valid Accounts
Phishing: Spearphishing Attachment
Drive-by Compromise
Account Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Asset Discovery and Classification
Control ID: Asset Management-01
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Botnet attacks targeting cloud infrastructure expose critical vulnerabilities in PHP servers and web-exposed assets requiring enhanced zero trust segmentation and threat detection capabilities.
Internet
Web-exposed gateways and IoT devices create extensive attack surfaces for Mirai-style botnets, necessitating comprehensive egress security, anomaly detection, and multicloud visibility controls.
Consumer Electronics
IoT device exploitation by infamous botnets compromises smart device ecosystems, demanding encrypted traffic protection, east-west traffic security, and inline intrusion prevention systems.
Computer Software/Engineering
PHP server vulnerabilities enable botnet infiltration of software platforms, requiring cloud firewall protection, Kubernetes security frameworks, and cloud native security fabric implementations.
Sources
- Botnets Step Up Cloud Attacks Via Flaws, Misconfigurationshttps://www.darkreading.com/cloud-security/botnets-cloud-attacks-flaws-misconfigurationsVerified
- Inside the Surge of PHP and IoT Exploits with Qualys TRUhttps://blog.qualys.com/vulnerabilities-threat-research/2025/10/30/what-security-teams-need-to-know-as-php-and-iot-exploits-surgeVerified
- Here Comes Mirai: IoT Devices RSVP to Active Exploitationhttps://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnetVerified
- Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnethttps://thehackernews.com/2025/05/hackers-exploit-samsung-magicinfo.htmlVerified
- Mirai Botnets Exploiting Wazuh Security Platform Vulnerabilityhttps://www.securityweek.com/mirai-botnets-exploiting-wazuh-security-platform-vulnerability/Verified
- Critical Wazuh bug exploited in Mirai botnet expansion drivehttps://www.theregister.com/2025/06/10/critical_wazuh_bug_exploited_in/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, microsegmentation, east-west policy enforcement, and egress controls would significantly reduce the botnet's ability to propagate, escalate privileges, and exfiltrate data within cloud environments. Real-time threat detection and network visibility further contain and disrupt botnet operations by quickly identifying and responding to malicious activity.
Control: Multicloud Visibility & Control
Mitigation: Rapid detection of exposed assets and misconfigurations prevents initial foothold.
Control: Zero Trust Segmentation
Mitigation: Limits attack paths by enforcing least privilege across workloads.
Control: East-West Traffic Security
Mitigation: Denies unauthorized internal communication and reduces the scope of compromise.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks or detects unauthorized outbound connections and C2 attempts.
Control: Encrypted Traffic (HPE) + Cloud Firewall (ACF)
Mitigation: Monitors and restricts encrypted data exfiltration and malicious egress flows.
Rapid anomaly detection triggers incident response to minimize business impact.
Impact at a Glance
Affected Business Functions
- Network Operations
- Data Management
- Customer Services
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive customer data, including personal information and credentials, due to unauthorized access facilitated by compromised IoT devices and servers.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and microsegmentation to contain lateral movement between cloud workloads.
- • Deploy centralized visibility and automated discovery to promptly identify misconfigurations and exposed services.
- • Implement strict east-west and egress policy enforcement, including FQDN filtering, to block command and control and exfiltration channels.
- • Utilize inline intrusion prevention and anomaly detection to identify and respond to botnet behaviors in real-time.
- • Regularly audit cloud environments for public-facing assets, weak controls, and unnecessary permissions to preempt exploitation.



