FortiGuard uncovers DDoS botnet targeting vulnerable TP-Link routers

June 22, 2023

FortiGuard Labs has discovered Condi, a new DDoS botnet that is targeting vulnerable TP-Link Archer AX21 (AX1800) routers. The botnet takes use of a flaw in the routers’ web-based interface, allowing attackers to remotely execute malicious malware.

Tagged CVE-2023-1389, a high-severity bug, it was discovered in these Linux-based devices. When routers get infected, they join the botnet and may be used to perform DDoS attacks against websites and other internet services. The botnet can also detect and remove other malicious programs that are running on compromised routers.

Condi is offering the option to buy the source code for two versions of its botnet: “standard” and “private.” The standard version scans the internet for vulnerable TP-Link routers and infects them with a remote shell script. However, Condi cannot stay active after a reboot, so it deletes certain Linux files related to rebooting. It also has a processID scanner to remove other malicious processes, but this feature has been found to have flaws and doesn’t work properly, according to FortiGuard researchers.

TP-Link has released a firmware update that addresses the vulnerability.

The sources for this piece include an article in TechSpot.

Top Stories

Related Articles

May 11, 2026 Instructure has restored access to its Canvas learning platform after a cyberattack disrupted service for universities and more...

May 6, 2026 The official White House mobile app for iOS and Android is facing scrutiny after a security researcher more...

May 4, 2026 Microsoft Defender mistakenly detected legitimate DigiCert root certificates as malware, triggering widespread false-positive alerts and, in some more...

April 27, 2026 Canada Life says it has contained a cybersecurity incident involving unauthorized access to internal applications through an more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn