A new DDoS-as-a-Service botnet named Condi was found exploiting a vulnerability in TP-Link Archer AX21 (AX1800) Wi-Fi routers to build an army of botnets to conduct attacks.
AX1800 is a popular Linux-based dual-band (2.4GHz + 5GHz) Wi-Fi 6 router with 1.8 Gbps bandwidth, mainly used by home users, small offices, shops, cafes, etc.
Condi which emerged in May 2023, aims to enlist new devices to create a powerful DDoS (distributed denial of service) botnet that can be rented to launch attacks on websites and services. The threat actors behind Condi also sells the malware’s source code.
According to a new Fortinet report published today, Condi targets CVE-2023-1389, a high-severity unauthenticated command injection and remote code execution flaw in the API of the router’s web management interface.
The flaw was discovered and reported to the network equipment vendor in January 2023, and TP-Link has released a security update in March with version 1.1.4 Build 20230219.
Condi is the second DDoS botnet to target this vulnerability after Mirai previously exploited it at the end of April.
An analysis of the malware artifact reveals its ability to terminate other competing botnets on the same host. It, however, lacks a persistence mechanism, so the program cannot survive a system reboot.
So, its authors decided to equip it with a wiper which prevents the devices from being shut down or restarted.
For propagation to vulnerable TP-Link routers, the malware scans for public IPs with open ports 80 or 8080 and sends a hardcoded exploitation request to download and execute a remote shell script that infects the new device.
The samples analyzed by Fortinet contained a scanner for CVE-2023-1389, while other Condi samples are found using different flaws to propagate, so its authors or operators could be experimenting on that front.
Besides, the analysts found samples that use a shell script with an ADB (Android Debug Bridge) source, potentially indicating that the botnet is spread through devices with an open ADB port (TCP/5555).
Presumably, this is the direct result of multiple threat actors having bought Condi’s source code, adjusting its attacks as they see fit.
The malware supports various TCP and UDP flood methods similar to those of Mirai. Older samples also contain HTTP attack methods; however, these appear to have been stripped in the latest malware version.
The users of the Archer AX21 AX1800 dual-band Wi-Fi 6 router can get the latest firmware update for their device’s hardware version from TP-Link’s downloads center.
Signs of an infected TP-Link router include device overheating, network disruptions, inexplicable changes in a device’s network settings, and admin user password resets.

















Comments