Cybersecurity researchers have reported a significant surge in automated attacks against PHP servers, IoT devices, and cloud gateways, primarily orchestrated by botnets such as Mirai, Gafgyt, and Mozi. These campaigns exploit a range of known vulnerabilities—including CVE-2017-9841 (PHPUnit), CVE-2021-3129 (Laravel), and CVE-2022-47945 (ThinkPHP)—as well as cloud misconfigurations and insecure deployments. The widespread use of PHP-based content management systems like WordPress and Craft CMS, combined with common misconfigurations and outdated plugins, has expanded the attack surface, making these environments especially attractive to threat actors seeking remote code execution or data theft opportunities.
Attackers are also leveraging insecure debugging tools, such as leaving Xdebug active in production, and are actively searching for exposed credentials, API keys, and AWS secrets on internet-facing servers. IoT devices remain a persistent weak link, with vulnerabilities like CVE-2022-22947 (Spring Cloud Gateway) and CVE-2024-3721 (TBK DVR-4104/4216) being targeted to conscript devices into botnets. The Qualys Threat Research Unit emphasizes that the combination of known software flaws and misconfigurations continues to drive the growth of large-scale botnet activity, posing ongoing risks to enterprises and cloud environments.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Security experts accompanying the Qualys findings warned that adversaries are increasingly pivoting beyond traditional IT into cloud infrastructure, IoT, OT, and IoMT devices. They said exposed APIs, default credentials, vulnerable firmware, and end-of-life devices are enabling low-cost scaling, credential theft, ransomware delivery, and botnet expansion.
The Qualys report said attackers were abusing query strings to trigger Xdebug debugging sessions on PHP servers, allowing data extraction from exposed environments. This highlighted insecure development tooling left enabled in production as an active attack vector.
Qualys Threat Research Unit reported a significant increase in automated attacks targeting web-exposed PHP servers, IoT devices, and cloud gateways. The report linked the activity to established botnets including Mirai, Gafgyt, and Mozi, exploiting known vulnerabilities and misconfigurations for remote code execution, data theft, and secondary malware delivery.
Netscout identified the Aisuru botnet as TurboMirai malware and said it could enable distributed denial-of-service attacks exceeding 20 Tbps. This assessment provided context for the scale and capability of modern Mirai-derived botnet activity.
Threat actors began exploiting the TBK DVR-4104/DVR-4216 command injection vulnerability CVE-2024-3721 as part of automated botnet intrusions against IoT devices. The flaw provided another path for Mirai, Mozi, and Gafgyt ecosystem operators to compromise exposed DVRs.
Botnet activity was reported abusing an MVPower DVR misconfiguration and backdoor exposure to compromise IoT devices. Mirai-linked operators used these weaknesses to add vulnerable DVRs to botnet capacity.
Attackers incorporated exploitation of Spring Cloud Gateway remote code execution vulnerability CVE-2022-22947 into campaigns against cloud gateways and cloud-native environments. The activity enabled compromise of exposed services and supported follow-on malware delivery and botnet growth.
Botnet operators were reported exploiting long-known remote code execution vulnerabilities in PHPUnit (CVE-2017-9841), Laravel Ignition (CVE-2021-3129), and ThinkPHP (CVE-2022-47945) to compromise internet-exposed PHP servers running platforms such as WordPress and Craft CMS. These weaknesses were used to seize control of servers and expand botnet infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourceinfosecurity-magazine.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.