Executive Summary
In June 2024, a new botnet malware known as ShadowV2 emerged, leveraging Mirai source code to target IoT devices, particularly from D-Link and TP-Link, exploiting known vulnerabilities for large-scale infection. Security researchers observed the malware operators using the widespread AWS outage as an opportunity to test command and control resilience, evade detection, and enhance lateral spread across hybrid and cloud networks. Initial access occurred via unpatched vulnerabilities in internet-facing devices, leading to rapid compromise and recruitment of thousands of endpoints, posing heightened risks to corporate and critical infrastructure systems. Detection was challenged by the use of encrypted and east-west traffic, with attackers adapting quickly to shifting network topologies.
This incident highlights the increasing sophistication of IoT-focused botnets and their opportunistic exploitation of cloud service disruptions. Organizations with hybrid or cloud-connected assets are strongly urged to reassess east-west traffic controls, segmentation, and anomaly detection, as automated threats now more readily exploit both vulnerable devices and network instability.
Why This Matters Now
ShadowV2's rapid adaptation to cloud outages and exploitation of IoT device vulnerabilities illustrate the urgency of securing both legacy hardware and modern cloud environments. The incident underscores rising risks of botnet-fueled attacks during service disruptions, spotlighting the need for real-time visibility and zero trust controls as attackers evolve faster than traditional defenses.
Attack Path Analysis
The ShadowV2 botnet began by exploiting known vulnerabilities in IoT devices from multiple vendors to gain initial access. After foothold, malware leveraged device weaknesses to escalate privileges. The botnet then propagated laterally within vulnerable network segments, infecting additional IoT and cloud-connected devices. ShadowV2 established command and control using outbound encrypted channels to coordinate attacks. Potential exfiltration of device data or network intelligence occurred, followed by sustained impact through denial-of-service actions or integrating new devices into the botnet.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited known vulnerabilities in public-facing IoT devices (e.g., D-Link, TP-Link) to gain initial access and deploy the ShadowV2 botnet malware.
Related CVEs
CVE-2020-25506
CVSS 9.8A command injection vulnerability in D-Link routers allows remote attackers to execute arbitrary commands.
Affected Products:
D-Link DIR-859 – All versions
Exploit Status:
exploited in the wildCVE-2022-37055
CVSS 9.8A remote code execution vulnerability in D-Link routers due to improper input validation.
Affected Products:
D-Link DIR-859 – All versions
Exploit Status:
exploited in the wildCVE-2024-10914
CVSS 9.8A command injection vulnerability in end-of-life D-Link routers allows remote attackers to execute arbitrary commands.
Affected Products:
D-Link DIR-859 – All versions
Exploit Status:
exploited in the wildCVE-2024-10915
CVSS 9.8A remote code execution vulnerability in end-of-life D-Link routers due to improper input validation.
Affected Products:
D-Link DIR-859 – All versions
Exploit Status:
exploited in the wildCVE-2009-2765
CVSS 9.8A remote code execution vulnerability in DD-WRT firmware allows unauthenticated attackers to execute arbitrary commands.
Affected Products:
DD-WRT Firmware – All versions
Exploit Status:
exploited in the wildCVE-2023-52163
CVSS 9.8A remote code execution vulnerability in DigiEver DVRs allows unauthenticated attackers to execute arbitrary commands.
Affected Products:
DigiEver DVR – All versions
Exploit Status:
exploited in the wildCVE-2024-3721
CVSS 9.8A remote code execution vulnerability in TBK devices allows unauthenticated attackers to execute arbitrary commands.
Affected Products:
TBK Devices – All versions
Exploit Status:
exploited in the wildCVE-2024-53375
CVSS 9.8A remote code execution vulnerability in TP-Link routers allows unauthenticated attackers to execute arbitrary commands.
Affected Products:
TP-Link Routers – All versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Network Service Discovery
Exploitation of Remote Services
System Information Discovery
Brute Force
Phishing
Replication Through Removable Media
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Address Vulnerabilities for All System Components
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 8
CISA ZTMM 2.0 – Device Discovery and Management
Control ID: Device Pillar: Asset Management
NIS2 Directive – Cybersecurity Risk-Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
ShadowV2 botnet targeting IoT devices creates massive risks for telecom infrastructure, requiring enhanced egress security, threat detection, and zero trust segmentation capabilities.
Internet
Internet service providers face critical exposure to Mirai-based ShadowV2 malware exploiting D-Link/TP-Link vulnerabilities, demanding multicloud visibility and inline IPS protection measures.
Utilities
Utility networks using vulnerable IoT devices face botnet infiltration risks, necessitating encrypted traffic monitoring, east-west security controls, and anomaly detection systems.
Consumer Electronics
Consumer electronics manufacturers like D-Link and TP-Link directly impacted by ShadowV2 exploits, requiring immediate vulnerability patching and enhanced device security frameworks.
Sources
- New ShadowV2 botnet malware used AWS outage as a test opportunityhttps://www.bleepingcomputer.com/news/security/new-shadowv2-botnet-malware-used-aws-outage-as-a-test-opportunity/Verified
- Botnet takes advantage of AWS outage to smack 28 countrieshttps://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/Verified
- ShadowV2 botnet exploits AWS issues to test attackshttps://hackmag.com/news/shadowv2-awsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic controls, threat detection, and egress policy enforcement would have limited ShadowV2's ability to propagate, communicate with C2 servers, and impact cloud workloads. CNSF capabilities such as microsegmentation, encrypted traffic inspection, and egress filtering directly constrain botnet propagation and malicious outbound activity.
Control: Cloud Firewall (ACF)
Mitigation: Prevents unauthorized inbound access to vulnerable devices.
Control: Kubernetes Security (AKF)
Mitigation: Restricts privilege escalation within containerized environments.
Control: Zero Trust Segmentation
Mitigation: Blocks unauthorized lateral movement across workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Detects and blocks suspicious outbound C2 communication.
Control: Encrypted Traffic (HPE) & Inline IPS (Suricata)
Mitigation: Alerts and stops unauthorized data exfiltration attempts.
Detects and contains compromised device behavior.
Impact at a Glance
Affected Business Functions
- Network Operations
- Customer Services
- E-commerce Platforms
Estimated downtime: 1 days
Estimated loss: $500,000
Potential exposure of customer data due to compromised IoT devices, leading to unauthorized access and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust segmentation and microsegmentation to block botnet lateral movement.
- • Enforce outbound egress filtering and FQDN policy to disrupt botnet communication and data exfiltration.
- • Deploy inline threat detection and anomaly response for early detection of malicious activity and rapid containment.
- • Utilize encrypted traffic inspection to uncover covert channels while maintaining privacy and compliance.
- • Harden IoT and cloud workloads with workload-specific firewall and privilege controls to reduce the initial attack surface.



