Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Mirai Botnets Exploiting Wazuh Security Platform Vulnerability 

CVE-2025-24016, a critical remote code execution vulnerability affecting Wazuh servers, has been exploited by Mirai botnets.

Proxy disrupted

A critical remote code execution vulnerability affecting Wazuh servers has been exploited by Mirai botnets, Akamai warned on Monday.

Wazuh is a free and open source security platform designed for threat detection and response. Its developers announced on February 10 that they had patched CVE-2025-24016, an unsafe deserialization issue affecting servers running version 4.4.0 and newer, prior to 4.9.1, which includes a patch.

“An unsafe deserialization vulnerability allows for remote code execution on Wazuh servers,” the developers explained. “The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent.”

A proof-of-concept (PoC) exploit enabling DoS attacks was made public at the time of disclosure, and a PoC designed for arbitrary code execution was released a few days later.

According to data from Akamai’s honeypots, in-the-wild exploitation attempts started in March. The cybersecurity firm has seen two Mirai campaigns exploiting CVE-2025-24016 to hack Wazuh servers. 

One Mirai botnet variant has targeted the flaw since early March, with the exploit designed to fetch and execute a malicious shell script that serves as a downloader for the Mirai malware payload. The same botnet also targeted vulnerabilities in Hadoop YARN, and TP-Link and ZTE routers. 

Advertisement. Scroll to continue reading.

The second Mirai variant targeting CVE-2025-24016 was observed in early May, and some evidence suggests that the campaign may have been aimed at the devices of Italian-speaking users.

“The propagation of Mirai continues relatively unabated, as it remains rather straightforward to repurpose and reuse old source code to set up or create new botnets. And botnet operators can often find success with simply leveraging newly published exploits,” Akamai warned.

Akamai has made available indicators of compromise (IoC) to help defenders detect and block these attacks.

More Mirai-related news comes from Kaspersky, which warned late last week that it had spotted a Mirai attack wave exploiting a remote command execution vulnerability tracked as CVE-2024-3721 to ensnare TBK DVR devices. 

Kaspersky too has made available IoCs associated with the Mirai attacks it has observed. 

UPDATE 06.12.2025: Wazuh has published a blog post to address CVE-2025-24016 and the recent attacks, saying that it believes none of its (paying) customers were impacted. The company has shared information on the conditions needed for exploitation, as well as mitigations.

Related: DanaBot Botnet Disrupted, 16 Suspects Charged

Related: US Announces Botnet Takedown, Charges Against Russian Administrators

Related: Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.