Researchers and mitigation providers tied the Mēris botnet to large-scale compromise of MikroTik routers, primarily through CVE-2018-14847, brute-forced SSH access, and abuse of RouterOS features such as scheduled tasks and SOCKS proxy enablement. Solar JSOC CERT linked the infection chain to infrastructure and techniques associated with Glupteba, identified about 95,500 unique compromised MikroTik devices from exfiltrated configuration data, and sinkholed cosmosentry[.]com, receiving traffic from roughly 45,000 infected devices over six days. Cloudflare separately described Mēris as a highly active Layer 7 botnet that used HTTP pipelining and open proxies to generate massive throughput, including attacks reaching 17.2 million requests per second and averaging more than 100 attacks per day.
The botnet was also used in DDoS extortion campaigns that embedded ransom notes directly in HTTP request URLs, with messages claiming to be from REvil and demanding 1 bitcoin per day while threatening reputational and financial harm. Imperva said one victim site was hit with a peak of 2.5 million requests per second, with more than 12 million malicious requests carrying an embedded extortion message and over 64 million requests blocked in under a minute. The activity followed earlier record-setting Mēris operations, including the 21.8 million RPS attack disclosed by Yandex, and targeted organizations in the United States and Europe, especially business, communications, and financial-sector sites.

Pull IOCs and campaign context straight into your stack.
17 events from the most recent confirmed update back to the earliest known activity.
Threatpost noted that Russia's FSB announced raids against REvil infrastructure and personnel in January 2022 at the request of the United States. The article cited this as context for later DDoS extortion messages claiming to be from REvil.
On September 20, 2021, NCCCI and Rostelecom-Solar announced they had identified and prevented an attempt to add more than 45,000 devices, mostly MikroTik equipment, to the Meris botnet. They said Solar JSOC CERT used errors in botnet control commands to identify and isolate the devices, then shared the infected-device list with foreign CERTs and notified Russian telecom operators.
On September 14, 2021, an infected MikroTik honeypot received a command directing it to the domain cosmosentry[.]com. Solar found the domain was unregistered and registered it as a sinkhole.
On September 10, 2021, Solar JSOC CERT observed attackers send FTP credentials and commands directing infected MikroTik devices to upload their configuration files. Solar collected and analyzed the uploads, identifying about 95,500 unique compromised devices.
Yandex disclosed a record DDoS attack that reached 21.8 million requests per second and said, along with Qrator Labs, that it was conducted using the Meris botnet. They reported that Meris consisted of compromised MikroTik network devices.
On September 9, 2021, Solar JSOC CERT observed a new task sent from command servers to infected MikroTik devices instructing them to fetch content from Yandex URLs over HTTPS. Solar assessed this task was likely related to organizing the DDoS attack against Yandex disclosed the same day.
On September 6, 2021, Meris launched 261 unique attacks against Cloudflare customers, the highest daily figure cited in the report. Cloudflare said Meris accounted for 17.5% of all Layer 7 DDoS attacks it observed that day.
After deploying new mitigation rules, Cloudflare said the largest Meris attack it observed reached 16.7 million requests per second on August 19, 2021. The event illustrated the botnet's ability to sustain record-scale Layer 7 DDoS traffic.
Cloudflare said it deployed additional mitigation rules in early August 2021 to more comprehensively block Meris attacks and improve threat visibility. After those changes, the largest Meris attack it observed was 16.7 million requests per second on August 19.
In July 2021, Avast observed vulnerable MikroTik routers exploited via CVE-2018-14847 to fetch staged payloads from attacker-controlled domains, including infrastructure used to distribute Glupteba malware. Avast linked the overlapping infrastructure to the Meris botnet and assessed the routers were being rented out as botnet-as-a-service infrastructure.
Cloudflare reported that QRator, in joint research with Yandex, originally detected the Meris botnet in late June 2021. Early estimates put the botnet at 30,000 to 56,000 bots, with some researchers later estimating it could be much larger.
Solar JSOC CERT said it had observed MikroTik infection attempts since at least 2019 using SSH password brute force and exploitation of CVE-2018-14847. The compromises installed RouterOS scheduler tasks, enabled SOCKS proxying, and fetched follow-on commands from attacker-controlled infrastructure.
MikroTik patched CVE-2018-14847 in 2018, a WinBox directory traversal flaw that enabled unauthorized file read/write access on vulnerable RouterOS devices. Later reporting tied continued exploitation of unpatched devices to the growth of the Meris botnet.
Imperva reported a DDoS extortion campaign in which attackers embedded ransom notes directly into HTTP request URLs, including messages claiming to be from REvil. One targeted site saw a peak of 2.5 million requests per second, with more than 64 million malicious requests blocked in under a minute, and Imperva assessed the activity as likely originating from Meris.
Cloudflare published an analysis describing Meris as a large active botnet composed primarily of compromised MikroTik routers and networking devices. The company said its automated DDoS defenses had been detecting and mitigating Meris attacks targeting thousands of websites worldwide.
Rostelecom-Solar said it reported its Meris sinkhole findings to Russian authorities, including the National Coordination Center for Computer Incidents (NKTsKI). The notification followed the company's observation that about 45,000 infected MikroTik devices were contacting the sinkholed cosmosentry.com domain.
Over six days after sinkholing cosmosentry[.]com, Solar JSOC CERT received traffic from roughly 45,000 infected devices, despite seeing about 78,000 unique IP addresses because of dynamic addressing. The sinkhole data provided direct visibility into the scale of the compromised MikroTik population.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcethreatpost.com
Open sourceblog.cloudflare.com
Open sourcetherecord.media
Open sourcehabr.com
Open sourcert-solar.ru
Open sourceblog.mikrotik.com
Open sourceimperva.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.