Ballista
- First seen
- 2023-05-10 00:00:00
- Malware type
- botnet, ddos
- Family
- Malware family
- Last IoC activity
- 2026-06-26 08:37:47
- Profile updated
- 2026-07-07 14:22:02
Targeted industries: technology-and-telecommunications
Context
Ballista is an IoT botnet, infecting unpatched TP-Link Archer AX21 (AX1800) routers. It spreads through automatic exploitation of CVE-2023-1389. Its capabilities include remote code execution and DDoS attacks.
Exploited vulnerabilities
- CVE-2023-1389 (vulnerability)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Ballista (report)
- catonetworks.com — Cato Ctrl Ballista New Iot Botnet Targeting Thousands Of Tp Link Archer Routers (report)