Multiple DDoS botnets exploited CVE-2023-28771, a critical command-injection vulnerability in several Zyxel firewall models, to compromise devices and recruit them for DDoS attacks. FortiGuard Labs observed exploitation during May and June 2023 using crafted Internet Key Exchange packets sent over UDP, allowing unauthenticated attackers to execute arbitrary code. Observed payloads targeted MIPS devices and included Dark.IoT, another Mirai-derived variant, and a botnet linked to the Telegram group “SHINJI.APP | Katana botnet.” Attackers used multiple delivery servers, frequently updated payloads, and connected compromised appliances to command-and-control infrastructure.
Security researcher Kevin Beaumont separately reported internet-wide Mirai exploitation and compromises of numerous small and medium-sized business VPN appliances, although his post did not provide supporting exploitation telemetry or a verified victim count. Zyxel issued an advisory on April 25, 2023, and CISA added the flaw to its Known Exploited Vulnerabilities catalog in May. Organizations operating affected Zyxel appliances should prioritize vendor firmware fixes and assess exposed devices for compromise rather than treating the vulnerability as a theoretical risk.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
FortiGuard observed a delivery script downloaded from 171[.]22[.]136[.]15, an address previously associated with Rapperbot, that redirected delivery to 171[.]22[.]136[.]18 for additional MIPS files. The associated Mirai-derived botnet decoded its configuration using index-based XOR and transmitted the victim’s public IP address to its command-and-control infrastructure.
FortiGuard observed a script downloading “lolmips” from 92[.]118[.]39[.]16, saving it as “.zw,” and executing it with the parameter “zywall.” Researchers identified the payload as Dark.IoT.
FortiGuard Labs first discovered a botnet that it subsequently analyzed in connection with the Zyxel exploitation campaign and linked to the Telegram group “SHINJI.APP | Katana botnet.”
CISA added the Zyxel command injection vulnerability to its Known Exploited Vulnerabilities catalog in May 2023.
FortiGuard Labs observed increased attack bursts beginning in May after publication of an exploit module for CVE-2023-28771. Attackers exploited the vulnerability through Internet Key Exchange packets transmitted over UDP.
Zyxel released a security advisory for a critical command injection vulnerability reported by TRAPA Security. The flaw allows unauthenticated attackers to execute arbitrary code on affected firewalls through specially crafted packets.
Dark.IoT, a Mirai-based botnet that targets systems beyond IoT devices, first emerged in 2021. It was later identified among payloads exploiting vulnerable Zyxel firewalls.
FortiGuard identified 11 DDoS methods in an analyzed payload and matched their names to another sample using a shinji[.]app command-and-control domain. Matching method updates posted by the operator connected the botnet to the Telegram group “SHINJI.APP | Katana botnet.”
Kevin Beaumont reported that Mirai was mass-exploiting CVE-2023-28771 across the internet and claimed numerous SMB VPN appliances had been compromised. His post linked an associated payload but supplied no verified victim count or supporting exploitation telemetry.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.