Categories: Cyber Security News

DNS Misconfiguration Exploited as New Botnet Launches Large Scale Cyber Attack

A newly uncovered botnet leveraging thousands of compromised network devices has been observed distributing malware-laden spam emails by exploiting DNS misconfigurations.

Infoblox Threat Intel reported that the botnet, built on hijacked MikroTik routers, is delivering trojans via spoofed sender domains that bypass standard email authentication mechanisms.

Sponsored
class="wp-block-heading" id="h-a-botnet-on-13-000-mikrotik-devices">A Botnet on 13,000 Mikrotik Devices

The campaign first surfaced in late November, when researchers discovered malspam emails imitating freight invoices from DHL.

The attachments, disguised as invoice or tracking ZIP files, contained obfuscated JavaScript loaders, which executed PowerShell commands to connect with a command-and-control (C2) server linked to prior malicious activity.

Analysis of email headers revealed infrastructure spanning roughly 13,000 hijacked MikroTik routers across multiple firmware versions.

Despite older routers having well-known vulnerabilities, including a hardcoded “admin” account with a blank password, the compromised fleet also included devices running recent firmware.

The attackers appear to have deployed scripts enabling SOCKS proxies, effectively transforming the devices into traffic relays.

This proxy setup not only anonymizes malicious activity but also opens the devices for abuse by other cybercriminals.

Researchers noted that while the botnet consists of 13,000 routers, its configuration as SOCKS relays potentially allows hundreds of thousands of additional systems to use the network as a cover for malware delivery, phishing, or data exfiltration.

DNS Misconfiguration Enables Email Spoofing

Central to the success of the campaign was the abuse of misconfigured DNS SPF (Sender Policy Framework) records.

How a misconfiguration in dns enabled a botnet-powered malspam campaign

SPF is designed to validate which servers are authorized to send email on behalf of a domain, providing a key layer of protection against spoofing. Properly configured records typically use “-all” to reject unauthorized senders.

Sponsored

However, investigators found that nearly 20,000 sender domains contained weakened or misconfigured SPF records, often using “+all.”

This setting effectively authorizes any server to send emails for the domain, nullifying protections and allowing threat actors to spoof legitimate companies.

With these DNS loopholes, malicious emails distributing trojans sailed past filtering systems, reaching targets who were more likely to trust them.

The implications extend well beyond spam delivery. With an arsenal of hijacked routers and a vast pool of spoofable domains, the botnet operator can escalate operations, ranging from distributed denial-of-service (DDoS) attacks to credential stuffing and data harvesting.

Experts stress that enterprises and individuals must regularly audit their DNS configurations, paying special attention to SPF, DKIM, and DMARC records. Secure device management is equally critical, particularly given MikroTik’s history of high-severity vulnerabilities and exposed default credentials.

This incident underscores a troubling reality in cybersecurity: seemingly minor misconfigurations, when scaled across thousands of devices and domains, enable attackers to weaponize the infrastructure of the internet itself.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post DNS Misconfiguration Exploited as New Botnet Launches Large Scale Cyber Attack appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

The Pitt Season 2, Episode 10: “4:00 PM” Review

Warning: This review contains full spoilers for The Pitt Season 2, Episode 10!The best episodes…

2 hours ago

The Total Wireless by Verizon “Apple iPhone 17e On Us” Deal Explained (New Release)

Apple recently released its newest budget smartphone - the Apple iPhone 17e - on March…

4 hours ago

Blight: Survival Remerges After 1.5 Million Steam Wishlists and a Viral Trailer With a New Look at Gameplay

Blight: Survival has reemerged with a new gameplay trailer — and its developers are promising…

4 hours ago

The Bluetti AC70 768Wh 1,000W LiFePO4 Power Station Is 20% Cheaper on AliExpress Than on Amazon

Bluetti is well known for its high quality yet affordable power stations and solar generators.…

5 hours ago

Stupid Never Dies Preview: An Outrageous Action RPG with Heart (Even if that Heart Isn’t Beating)

There’s something endlessly endearing about a good-natured dummy. Just a happy, optimistic doofus that can…

5 hours ago

WATCH LIVE: Sweetwater Rattlesnake Roundup Parade

(KTAB/KRBC) - The Sweetwater Rattlesnake Roundup Parade for 2026 is taking place at 4:30 p.m.,…

6 hours ago

This website uses cookies.