The Andoryu botnet has been observed exploiting the critical Ruckus Wireless access point web vulnerability CVE-2023-25717 to compromise exposed admin panels and turn affected devices into bots. The flaw, disclosed by Ruckus as an RCE/CSRF issue in AP web management interfaces, allows attackers to deploy a propagation script and expand infections across vulnerable wireless infrastructure.
Researchers said the compromised access points are being used primarily for DDoS attacks, with Andoryu supporting ICMP, TCP, and UDP flooding and communicating with command-and-control servers over SOCKS5. The activity also shows the botnet broadening its exploit arsenal beyond earlier abuse of GitLab CVE-2021-22205 and Lilin DVR flaws, underscoring how enterprise and edge devices continue to be repurposed for large-scale attack operations.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
According to Fortinet researcher Cara Lin, the latest Andoryu campaign began in late April 2023 and started exploiting the critical Ruckus flaw CVE-2023-25717. After compromise, attackers dropped a remote script for proliferation and used infected devices to await commands for ICMP, TCP, and UDP DDoS attacks.
Ruckus published a security bulletin for CVE-2023-25717, a critical unauthenticated remote code execution flaw in the AP web admin panel caused by improper handling of HTTP requests. The vulnerability was described as allowing complete compromise of affected wireless access point equipment, and the flaw was patched.
QiAnXin first documented the Andoryu botnet in February 2023. The malware was noted as using SOCKS5 for command-and-control communications and previously weaponizing GitLab CVE-2021-22205 and Lilin DVR flaws for propagation.
Fortinet observed the latest RapperBot miner activity in January 2023, showing newer variants adding XMRig-based Monero mining to the botnet's established DDoS operations. The attacks delivered a Bash script that downloaded and executed separate XMRig miners and RapperBot binaries, with later updates merging both functions into one client.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.