Researchers from CloudSEK Threat Intelligence (TRIAD) have uncovered a rapidly expanding Loader-as-a-Service (LaaS) campaign, known as the Morte botnet, which systematically compromises SOHO routers, IoT devices, enterprise applications, and CMS platforms. The campaign has been active for at least six months and has demonstrated a significant 230% increase in attack volume between July and August 2025. Attackers exploit web-based command injection vulnerabilities, particularly through unsanitized POST parameters such as ntp, syslog, and hostname fields, allowing them to execute arbitrary shell commands on targeted devices. The botnet also leverages default credentials, such as admin:admin, using brute force and credential spraying techniques to gain unauthorized access. Key targets include Oracle WebLogic servers, WordPress sites, vBulletin forums, and other Linux-based systems, with exploitation of known vulnerabilities like CVE-2019-16759 (vBulletin), CVE-2019-17574 (WordPress Popup Maker), and CVE-2012-1823 (PHP-CGI RCE). Once access is obtained, attackers deploy small shell scripts as droppers, which then deliver native binaries such as the Morte malware and cryptomining payloads. The infrastructure supporting the botnet is highly dynamic, rotating across dozens of IP addresses to evade detection and takedown efforts. The campaign has also been observed distributing Mirai-like bots, further expanding its reach and impact. Post-exploitation, the botnet uses commands like [ReplyDeviceInfo] for reconnaissance and [ConfigSystemCommand] for command injection, enabling persistent control over compromised devices. Security researchers gained insight into the operation by accessing exposed command-and-control (C2) logs, which detailed the attackers' methods and infrastructure. Organizations are advised to mitigate risk by blocking egress traffic, enforcing strong and unique credentials, updating device firmware, segmenting IoT and embedded devices, and replacing end-of-life hardware. Additional recommendations include adopting Sigma rules to detect suspicious POST parameter activity and collecting forensic artifacts for incident response. The campaign's use of multi-architecture malware and BusyBox tools allows it to target a wide range of devices, increasing its effectiveness and threat level. The loader-as-a-service model enables other threat actors to leverage the botnet's infrastructure for their own payloads, further complicating defense efforts. The rapid growth and sophistication of the Morte botnet highlight the ongoing risks posed by insecure web interfaces and outdated devices in both enterprise and home environments. The campaign's ability to exploit both known and zero-day vulnerabilities underscores the importance of timely patching and proactive security measures. CloudSEK's findings emphasize the need for continuous monitoring and threat intelligence sharing to counter evolving botnet threats. The exposure of C2 logs has provided valuable intelligence, but the botnet's operators continue to adapt their tactics to maintain operational resilience. The Morte botnet campaign represents a significant and ongoing threat to organizations relying on internet-exposed devices and applications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
On 2025-09-29, reporting described a novel loader-as-a-service operation dubbed the Morte botnet that was deploying Mirai bots. The campaign was said to target routers and enterprise applications and to be growing rapidly.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.