Ballista is an IoT botnet targeting TP-Link Archer routers by exploiting CVE-2023-1389, an unauthenticated remote code execution flaw in the routers’ web management interface. Reported by Cato CTRL as a previously unreported campaign first identified on 2025-01-10 and still active at the time of reporting, Ballista was observed targeting organizations in manufacturing, medical and healthcare, services, and technology sectors in the United States, Australia, China, and Mexico. The campaign specifically referenced TP-Link Archer AX21 (AX1800), and Censys data indicated more than 6,000 vulnerable TP-Link devices were exposed to the Internet at the time of reporting.
The vulnerable endpoint is /cgi-bin/luci;stok=/locale, where unsanitized input in the country form enables command execution as root. Initial access uses a bash dropper script named dropbpb.sh, which downloads payloads from attacker-controlled infrastructure at 2.237.57[.]70 over HTTP port 81. The dropper writes itself to disk, sets permissions with chmod 777, executes in the background, removes itself, traverses local directories, and downloads multi-architecture binaries for mips, mipsel, armv5l, armv7l, and x86_64.
Once executed, the malware kills prior instances of itself and removes binaries from disk to reduce detection. It reads local files including /etc/passwd, /etc/shadow, /etc/sudoers, /etc/pam.d/, /etc/hosts, /etc/resolv.conf, and /etc/ssl/openssl.conf. Ballista establishes a TLS-encrypted command-and-control channel to 2.237.57[.]70 on port 82; observed default client packets included the strings "hiimrealinfected" and "client_info_architecture x86_64". Supported C2 command keywords include flooder, exploiter, start, close, shell, and killall. Capabilities include remote shell command execution, automated propagation by exploiting CVE-2023-1389 against other devices over HTTP port 8080, and DoS/DDoS attacks via a modular FLOODER component, with an identified attack implementation using the keyword tcpgeneric. The malware maintains a module queue and spawns threads to process requested modules.
Cato assessed with moderate confidence that Ballista is linked to an Italian-based threat actor, based on the geolocation of C2 IP 2.237.57[.]70 and Italian-language strings in the binaries. Researchers also observed a newer dropper variant hosted on GitHub that used Tor .onion infrastructure instead of the hard-coded IP, indicating an evolution toward greater operational stealth.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The botnet exploits a remote code execution (RCE) vulnerability in TP-Link Archer routers (CVE-2023-1389) to spread itself automatically over the Internet. Specifically, the AX21 model (aka AX1800 model)... This vulnerability in the TP-Link Archer router’s web management interface stems from the lack of sanitization of user input in the country form of the /cgi-bin/luci;stok=/locale endpoint, resulting in unauthenticated command execution with root privileges. | Due to the Italian links, and the targeted TP-Link Archer routers, we have named the botnet “Ballista” as a reference to the ancient Roman weapon.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The Ballista botnet exploits a remote code execution (RCE) vulnerability in TP-Link Archer routers (CVE-2023-1389)... This vulnerability in the TP-Link Archer router’s web management interface (T1190) stems from the lack of sanitization of user input...
Obfuscated Files or Information: Binary Padding (T1027.001) Repeated no-op instructions were observed during reverse engineering analysis
Obfuscated Files or Information: Stripped Payloads (T1027.008) The malware binaries are stripped & statically linked
System Network Configuration Discovery (T1016) The malware reads /etc/hosts & other network configuration related files
System Network Configuration Discovery: Internet Connection Discovery (T1016.001) The malware sends GET requests to check connectivity before attempting to exploit CVE-2023-1389
The default malware execution flow displays the following capabilities: Kills previous instances of itself (T1057)... Taking a deeper look into the assembly code reveals the use of multiple ps commands to list running processes...
This bash one-liner writes a while loop that attempts to download the dropper... via HTTP (T1071.001)...
A new variant of the dropper was observed using .onion TOR domains instead of the hard-coded IP.
Sets up an encrypted C2 channel on port 82 (T1573, T1095), through which additional functionality can be invoked.
Eventually, the script drops five pre-compiled binaries onto the target system (T1105) named bpb.$ arch... using the curl command or wget as a fallback.
This bash one-liner writes a while loop that attempts to download the dropper from an attacker-controlled server (2.237.57[.]70) on port 81 (T1571)...
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet that exploits TP-Link Archer router RCE (CVE-2023-1389) to self-propagate and compromise devices.
IoT botnet targeting TP-Link routers, likely for DDoS or other malicious activities.
Ballista is a previously unreported global IoT botnet targeting TP-Link Archer routers. It exploits CVE-2023-1389 for unauthenticated remote code execution, deploys a shell dropper, installs architecture-specific binaries, establishes a TLS-encrypted C2 channel on port 82, spreads automatically to other vulnerable devices, executes shell commands, reads sensitive local files, and can launch DoS/DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.