Categories: Cyber Security News

DNS Misconfiguration Exploited as New Botnet Launches Large Scale Cyber Attack

A newly uncovered botnet leveraging thousands of compromised network devices has been observed distributing malware-laden spam emails by exploiting DNS misconfigurations.

Infoblox Threat Intel reported that the botnet, built on hijacked MikroTik routers, is delivering trojans via spoofed sender domains that bypass standard email authentication mechanisms.

A Botnet on 13,000 Mikrotik Devices

The campaign first surfaced in late November, when researchers discovered malspam emails imitating freight invoices from DHL.

The attachments, disguised as invoice or tracking ZIP files, contained obfuscated JavaScript loaders, which executed PowerShell commands to connect with a command-and-control (C2) server linked to prior malicious activity.

Analysis of email headers revealed infrastructure spanning roughly 13,000 hijacked MikroTik routers across multiple firmware versions.

Despite older routers having well-known vulnerabilities, including a hardcoded “admin” account with a blank password, the compromised fleet also included devices running recent firmware.

The attackers appear to have deployed scripts enabling SOCKS proxies, effectively transforming the devices into traffic relays.

This proxy setup not only anonymizes malicious activity but also opens the devices for abuse by other cybercriminals.

Researchers noted that while the botnet consists of 13,000 routers, its configuration as SOCKS relays potentially allows hundreds of thousands of additional systems to use the network as a cover for malware delivery, phishing, or data exfiltration.

DNS Misconfiguration Enables Email Spoofing

Central to the success of the campaign was the abuse of misconfigured DNS SPF (Sender Policy Framework) records.

How a misconfiguration in dns enabled a botnet-powered malspam campaign

SPF is designed to validate which servers are authorized to send email on behalf of a domain, providing a key layer of protection against spoofing. Properly configured records typically use “-all” to reject unauthorized senders.

However, investigators found that nearly 20,000 sender domains contained weakened or misconfigured SPF records, often using “+all.”

This setting effectively authorizes any server to send emails for the domain, nullifying protections and allowing threat actors to spoof legitimate companies.

With these DNS loopholes, malicious emails distributing trojans sailed past filtering systems, reaching targets who were more likely to trust them.

The implications extend well beyond spam delivery. With an arsenal of hijacked routers and a vast pool of spoofable domains, the botnet operator can escalate operations, ranging from distributed denial-of-service (DDoS) attacks to credential stuffing and data harvesting.

Experts stress that enterprises and individuals must regularly audit their DNS configurations, paying special attention to SPF, DKIM, and DMARC records. Secure device management is equally critical, particularly given MikroTik’s history of high-severity vulnerabilities and exposed default credentials.

This incident underscores a troubling reality in cybersecurity: seemingly minor misconfigurations, when scaled across thousands of devices and domains, enable attackers to weaponize the infrastructure of the internet itself.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post DNS Misconfiguration Exploited as New Botnet Launches Large Scale Cyber Attack appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

With new neighborhoods opening in and around Sioux Falls, homebuilders hope for rebound year

April 13, 2026 What’s the market in Sioux Falls for a residential home lot priced…

5 minutes ago

AI research company AMILabs.xyz, co-founded by Yann LeCun, is focused on building world models for real-world intelligence

AMILabs.xyz – Gandi customer – (United States) Forward-looking AI research labs and developers use .xyz…

10 minutes ago

Watch 35 Short Films by Charles and Ray Eames: “Powers of Ten,” the History of the Computer & More

?si=sPXB5teJO7wsm71F The Pacific Palisades fire of January 25 destroyed much of that coastal Los Angeles…

20 minutes ago

Patriots Point Sells Tickets for July 4 Fireworks Event Aboard USS Yorktown

Patriots Point Naval & Maritime Museum now offers tickets for its yearly Independence Day fireworks…

24 minutes ago

Patriots Point Sells Tickets for July 4 Fireworks Event Aboard USS Yorktown

Patriots Point Naval & Maritime Museum now offers tickets for its yearly Independence Day fireworks…

24 minutes ago

Newark Launches 24/7 Fridge To Aid Residents Facing High Food Prices

United Community Corporation cut the ribbon on Wednesday, April 8, at 12:30 p.m. A new…

24 minutes ago

This website uses cookies.