CUJO AI’s IoT botnet research found a sharp increase in malware carrying vulnerability exploits, while an older Huawei router flaw remained overwhelmingly dominant. Across protected consumer networks monitored from July 2022 through January 2023, researchers identified 6,471 malicious ELF binaries, including 1,685 containing exploits. The exploit-bearing share rose from 8% in the company’s 2021 study to 26%, and the number of targeted vulnerabilities increased from 20 to 55. CVE-2017-17215, affecting Huawei HG532 routers, appeared in 1,625 exploit-bearing binaries. Zerobot carried the largest exploit set, with 22 entries; Sysrv, Enemybot and an unnamed Go-based sample also incorporated relatively recent vulnerabilities.
The findings highlight persistent exposure from unpatched legacy devices alongside newer attack paths. Separate references identify security issues in Eir’s D1000 modem and Realtek SDK components used across hundreds of thousands of downstream devices, underscoring the need to track both device firmware and embedded dependencies. Qualys’ PwnKit advisory covers CVE-2021-4034, a local privilege-escalation flaw in polkit’s pkexec, rather than a standalone remote entry point. Defenders should prioritize exposed-device inventories, firmware remediation, replacement of unsupported equipment and network segmentation. CUJO AI also documented malformed or potentially nonfunctional exploit implementations: an exploit’s presence in malware does not establish successful compromise.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
CUJO AI investigated IoT botnet activity in protected consumer networks from early July 2022 through the end of January 2023. The investigation classified 6,471 distinct ELF binaries as malicious, including 1,685 containing exploits targeting a total of 55 vulnerabilities.
During a four-month study in 2021, CUJO AI found that 8% of analyzed malicious binaries contained vulnerability exploits, targeting 20 vulnerabilities. Approximately 83% of exploit-bearing binaries contained multiple exploits.
CUJO AI reported that Huawei HG532 vulnerability CVE-2017-17215 appeared in approximately 96% of exploit-bearing binaries, while Go-based Zerobot carried the largest exploit set, with 22 entries. The report also documented Sysrv, Enemybot, and an unnamed Go-based sample carrying newer exploits, but identified malformed or potentially nonfunctional implementations and cautioned that exploit presence did not establish successful compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
owasp.org
Open sourceonekey.com
Open sourcecujo.com
Open sourcequalys.com
Open sourcedevicereversing.wordpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.