Infoblox reported a large malspam operation that used about 13,000 compromised MikroTik routers to send malicious email and relay traffic through open SOCKS4 proxies, helping the activity blend in with legitimate network traffic. The campaign impersonated DHL with freight-invoice lures and delivered ZIP archives containing obfuscated JavaScript that launched PowerShell and contacted a malware command-and-control server at 62.133.60[.]137. Researchers said the infrastructure could support not only spam and malware delivery, but also phishing, DDoS, and other covert operations.
A major factor in the campaign’s success was widespread SPF misconfiguration across roughly 20,000 sender domains, especially records that allowed +all, enabling attackers to spoof trusted domains and evade normal email checks. Separate research on MikroTik RouterOS showed that exposed devices remained vulnerable to CVE-2023-30799, a privilege-escalation flaw that can lead to root access on affected hardware, while weak default credentials, username enumeration, and limited brute-force protections reduced the practical value of the authentication barrier. Together, the findings show how insecure router management and weak email authentication created durable infrastructure for a Russian-linked botnet.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
On 2023-07-20, RouterOS 6.49.8 was released, but the write-up states the Long-term branch still lagged on fixes for CVE-2023-30799 until VulnCheck contacted MikroTik.
On 2023-07-19, the MikroTik RouterOS privilege-escalation issue received CVE-2023-30799 after VulnCheck published broader exploitation affecting additional hardware.
On 2023-07-18, VulnCheck said RouterOS Long-term 6.48.6 was the second most installed RouterOS version in Shodan data, with hundreds of thousands of devices exposed through web and Winbox interfaces.
In October 2022, MikroTik fixed the vulnerability later tracked as CVE-2023-30799 in RouterOS stable 6.49.7. The release notes reportedly described it only as improved handling of user policies rather than an explicit security fix.
In June 2022, Margin Research's Ian Dupont and Harrison Green publicly presented the FOISted exploit for MikroTik RouterOS x86 VM, demonstrating root-shell access without a CVE assignment at that time.
Through email header analysis, Infoblox determined that approximately 13,000 compromised MikroTik devices were participating in the botnet and proxying malicious traffic through unauthenticated SOCKS4 relays.
Infoblox reported that the botnet abused roughly 20,000 sender domains with dangerous SPF records permitting "+all," allowing spoofed emails to bypass normal protections and improve delivery.
In late November, Infoblox discovered a large malspam operation using compromised MikroTik routers as open SOCKS4 relays to send DHL-themed freight invoice lures carrying malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.