A Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection flaw in end-of-life D-Link DIR-823X routers, marking the first reported in-the-wild abuse of the vulnerability since its public disclosure and proof-of-concept release in 2025. Akamai said it began seeing attacks in early March 2026 through crafted POST requests to the /goform/set_prohibiting endpoint, where unsanitized input reaches system() and enables remote command execution on affected firmware versions 240126 and 240802. The activity targets discontinued devices unlikely to receive vendor fixes, increasing exposure for organizations still running the routers.
The attackers use the exploit to fetch and run a shell script that installs a Mirai variant dubbed tuxnokill, which retains common Mirai strings while using XOR obfuscation with key 0x30. Akamai linked the same actor to similar Mirai deployment patterns against TP-Link AX21 devices via CVE-2023-1389 and against ZTE ZXV10 H108L routers through another remote code execution flaw, underscoring continued botnet weaponization of older, publicly documented vulnerabilities. Security advisories recommend replacing unsupported D-Link hardware, restricting exposed administrative interfaces, and rapidly remediating known router flaws before they are folded into botnet operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
HKCERT published a security bulletin warning that Mirai botnet activity was targeting end-of-life D-Link routers affected by CVE-2025-29635. The alert reflected broader defender notification following Akamai's findings.
Akamai published research detailing the Mirai campaign targeting end-of-life D-Link DIR-823X routers via CVE-2025-29635 and warned that older, publicly documented flaws continue to be weaponized. The report urged organizations to replace retired devices and improve patching and exposure management.
Akamai assessed that the same threat actor was also exploiting CVE-2023-1389 in TP-Link AX21 routers and a remote code execution flaw in ZTE ZXV10 H108L routers using a similar Mirai deployment pattern. This expanded the campaign beyond D-Link devices to multiple router brands.
The observed campaign downloaded and executed a shell script named dlink.sh to install a Mirai variant called tuxnokill on compromised D-Link routers. Reporting also identified infrastructure including payload host 88.214.20[.]14 and command-and-control server 64.89.161[.]130:44300.
In early March 2026, Akamai SIRT detected in-the-wild exploitation of CVE-2025-29635 against D-Link DIR-823X routers, marking the first observed active abuse of the flaw. Attackers used crafted POST requests to the /goform/set_prohibiting endpoint to execute commands on vulnerable devices.
Researchers Wang Jinshuai and Zhao Jiangting publicly disclosed CVE-2025-29635, a command-injection flaw in D-Link DIR-823X routers, and proof-of-concept exploit details became available around the same time. The vulnerability later became the basis for Mirai botnet exploitation.
The affected D-Link DIR-823X devices reached end-of-life status, reducing the likelihood of vendor security fixes for CVE-2025-29635. Subsequent reporting recommended replacing the unsupported routers or restricting exposed administration access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehkcert.org
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceakamai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.