A threat actor using the alias Anarchy reportedly assembled a botnet of roughly 18,000 compromised Huawei HG532 routers in a single day by exploiting CVE-2017-17215, a remote command execution flaw that had already been abused by Mirai-derived malware and Satori variants. The campaign highlighted how long-known weaknesses in internet-facing SOHO and IoT devices continue to provide attackers with a large pool of systems for botnet growth and potential DDoS or other criminal activity.
Public exploit details for CVE-2017-17215 showed that attackers could send a crafted SOAP request to the router's UPnP WANPPPConnection service on port 37215 and inject shell commands through the NewStatusURL field of the Upgrade action, using the default credentials dslf-config/admin. Reporting also indicated that the actor planned to expand operations by targeting CVE-2014-8361 in Realtek-based routers via port 52869, suggesting broader efforts to scale router-based botnet infections across poorly secured edge devices.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Exploit-DB published a verified proof-of-concept for arbitrary command execution on Huawei HG532 routers, identified as CVE-2017-17215. The entry showed how a crafted SOAP request to the router's WANPPPConnection service could execute shell commands remotely.
Huawei published a security notice confirming the existence of CVE-2017-17215, a remote code execution flaw affecting HG532 devices, after receiving the report from Check Point researcher Muhammad Mukatren on November 27, 2017. The company advised mitigations, noted IPS signature updates, and said fix versions were provided for non-End of Service products.
Cymulate Threat Research Group identified a Mirai-related shell variant exploiting CVE-2017-17215 on Huawei HG532 routers. The campaign retrieved UPX-packed, multi-architecture ELF payloads from 85.217.144[.]35/condi/ and executed them on compromised devices.
According to researcher Ankit Anubhav, Anarchy said he also planned to target CVE-2014-8361 in Realtek routers, exploitable via port 52869. This marked an intended expansion beyond Huawei HG532 devices.
Threat actor 'Anarchy' reportedly assembled a botnet of about 18,000 compromised devices in a single day by exploiting Huawei HG532 routers via CVE-2017-17215. The actor also shared a list of infected victim IP addresses with researcher Ankit Anubhav, who did not publish it.
A July 19 blog post cited by later reporting noted an increase in the number of compromised Huawei routers. This indicated active exploitation of CVE-2017-17215 in the wild before broader coverage of the botnet's scale.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
cymulate.com
Open sourcecve.mitre.org
Open sourcescmagazine.com
Open sourceexploit-db.com
Open sourcehuawei.com
Open sourcehuawei.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.