Ballista

First seen
2023-05-10 00:00:00
Malware type
botnet, ddos
Family
Malware family
Last IoC activity
2026-06-26 08:37:47
Profile updated
2026-07-07 14:22:02

Targeted industries: technology-and-telecommunications

Context

Ballista is an IoT botnet, infecting unpatched TP-Link Archer AX21 (AX1800) routers. It spreads through automatic exploitation of CVE-2023-1389. Its capabilities include remote code execution and DDoS attacks.

Exploited vulnerabilities

  • CVE-2023-1389 (vulnerability)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Ballista (report)
  • catonetworks.com — Cato Ctrl Ballista New Iot Botnet Targeting Thousands Of Tp Link Archer Routers (report)

External references