Attackers exploited CVE-2022-46169, a critical unauthenticated command injection vulnerability in the Cacti network monitoring tool, to deploy Mirai-family malware and Perl-based IRC bots. The flaw, rated CVSS 9.8, allows remote code execution through Cacti’s remote_agent.php endpoint. FortiGuard Labs observed attack bursts in January and March 2023 involving this flaw and CVE-2021-35394 in Realtek devices to distribute Moobot and ShellBot. Moobot is a Mirai-derived botnet that terminates competing bot processes; observed ShellBot variants support distributed denial-of-service attacks, reverse shells, port scanning, and, in some cases, additional malware installation.
Censys identified 6,427 internet-exposed Cacti hosts in January 2023, including 1,637 confirmed vulnerable instances; versions could not be determined for every host, and only 26 hosts with identifiable versions were running a release unaffected by the flaw. Beyond botnet recruitment, compromised Cacti systems can expose network-device details and internal IP addresses that help attackers expand their foothold. A Cacti fix was already available, making prompt patching of affected Cacti deployments and Realtek devices, reduced internet exposure, and strong passwords key defensive priorities.

See which actors are running it and whether you're in range.
13 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs observed further attack bursts targeting Cacti CVE-2022-46169 and Realtek CVE-2021-35394 to distribute Moobot and ShellBot malware.
The server associated with the 'LiGhT's Modded perlbot v2' ShellBot variant was created in March 2023. FortiGuard subsequently observed hundreds of victims in its IRC channel.
Shadowserver observed exploitation attempts against CVE-2022-46169 delivering malware. Observed payloads included Mirai and a Perl-based IRC botnet that opened reverse shells and instructed compromised hosts to perform port scans.
SonarSource published a technical write-up of its Cacti vulnerability finding and a short demonstration video.
Shadowserver observed increased CVE-2022-46169 exploitation attempts during the week preceding the January 15 report. Its total observed attempts remained below two dozen.
FortiGuard Labs observed attack bursts exploiting Realtek CVE-2021-35394 and Cacti CVE-2022-46169 to distribute Moobot and ShellBot. ShellBot activity began in January and primarily targeted Cacti.
Technical details and proof-of-concept exploit code for CVE-2022-46169 began appearing publicly.
An advisory published in early December warned of CVE-2022-46169, a Cacti command injection vulnerability rated 9.8 out of 10. The flaw permits unauthenticated arbitrary code execution.
FortiGuard Labs observed Moobot, a Mirai-derived botnet, attacking Hikvision products.
FortiGuard published analysis and indicators for Moobot and three captured ShellBot variants: 'PowerBots (C) GohacK,' 'LiGhT's Modded perlbot v2,' and 'B0tchZ 0.2a.' The analysis documented Moobot's termination of competing bots, IRC-based ShellBot command and control, and additional-malware installation capabilities in some ShellBot variants.
Censys identified 6,427 internet-exposed Cacti hosts and confirmed that 1,637 were vulnerable to CVE-2022-46169. Only 26 hosts with identifiable versions ran a non-vulnerable release, although version information was unavailable for many hosts.
More recent attempts observed by Shadowserver checked whether Cacti instances were vulnerable rather than delivering malware.
Cacti's developer released an update fixing the vulnerability and provided guidance to prevent command injection and authorization bypass.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 54 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.