Saturday, 13 December 2025
25.9 C
Singapore
20.3 C
Thailand
20.7 C
Indonesia
26.9 C
Philippines

ShadowV2 botnet spotted during AWS outage, researchers warn of possible return

ShadowV2 botnet briefly emerged during the AWS outage, targeting IoT devices, raising concerns about future cyberattacks.

A new botnet, believed to be built on the foundations of the notorious Mirai malware, briefly appeared during the recent Amazon Web Services (AWS) outage, security researchers have reported. The incident has raised concerns that the botnet could return for a larger-scale attack in the future.

Brief emergence during AWS outage

Security experts from FortiGuard Labs revealed that the ShadowV2 botnet was active for no more than 15 hours during the AWS disruption. During this short window, it targeted vulnerabilities across devices from multiple manufacturers, including DD-WRT, D-Link, DigiEver, TBK, and TP-Link. The malware focused on creating a network of compromised devices, including routers, Wi-Fi access points, NAS boxes, DVRs, network video recorders, and other Internet of Things (IoT) hardware.

According to FortiGuard Labs, ShadowV2’s brief activity suggests it was conducting a trial run rather than executing a full-scale attack. “Its emergence likely served as a test run,” the researchers said, warning that the botnet is expected to resurface in the future.

Evolution from mirai

ShadowV2 is described as a cloud-native botnet that initially targeted AWS EC2 instances. However, it has since evolved to target multiple sectors, spanning technology, retail, hospitality, government, and telecommunications. The botnet has been observed in over two dozen countries, including the United States, Canada, the United Kingdom, China, Russia, and Saudi Arabia.

Mirai, the malware that inspired ShadowV2, became infamous for pioneering large-scale IoT botnets capable of crippling major websites and internet infrastructure worldwide. Like its predecessor, ShadowV2 is likely designed to scan the internet for vulnerable devices, brute-force credentials, infect devices, and use them to expand its network. It could be deployed to launch Distributed Denial-of-Service (DDoS) attacks or other disruptive campaigns.

Wider implications for cloud security

The emergence of ShadowV2 coincided with a separate, significant cyber incident in which Microsoft Azure was targeted by the “largest-ever” cloud-based DDoS attack. The Aisuru botnet carried out this assault, sometimes referred to as “Turbo Mirai,” which is also considered a descendant of the original Mirai malware.

While the total number of devices infected with ShadowV2 remains unknown, the botnet primarily targets IoT devices. Security researchers emphasise the need for organisations to stay vigilant and ensure all connected devices are regularly updated and protected against known vulnerabilities.

Cybersecurity experts warn that ShadowV2 represents the ongoing evolution of IoT malware, highlighting the persistent threat posed by botnets in a connected world. With its brief test run already observed globally, the botnet could be poised to return with greater impact.

Hot this week

Singapore leads global third-party cyber risk maturity as supply-chain threats intensify

Singapore leads global third-party cyber risk maturity but faces rising supply-chain cyber threats, according to new BlueVoyant research.

Veeam completes acquisition of Securiti AI to build unified trusted data platform

Veeam completes its US$1.725 billion acquisition of Securiti AI to form a unified trusted data platform for secure and scalable AI adoption.

New research finds growing public demand for modern emergency call systems in Australia and New Zealand

New study shows strong public support for modern, data-driven and AI-enabled emergency call systems in Australia and New Zealand.

Airwallex acquires majority stake in Indonesian payments firm to deepen Asia-Pacific expansion

Airwallex acquires majority ownership of PT Skye Sab Indonesia to expand its financial infrastructure across Asia-Pacific.

Lofree introduces the Flow 2 low-profile mechanical keyboard for Mac users

Lofree’s Flow 2 brings improved low-profile mechanical typing to Mac users, with new POM switches, wireless support, and a solid build.

PlayStation introduces limited edition Genshin Impact DualSense controller

PlayStation announces a limited edition Genshin Impact DualSense controller for PS5, launching in Singapore on 21 January 2026.

PGL brings Counter-Strike 2 Major to Singapore in November 2026

PGL confirms the Counter-Strike 2 Major is coming to Singapore in November 2026, marking the first CS2 Major in Southeast Asia.

Denodo: Rethinking data architecture for AI agility and measurable ROI in Asia-Pacific

Denodo highlights how modern, composable data architectures powered by logical data management are helping Asia-Pacific enterprises accelerate AI adoption, ensure governance, and achieve measurable ROI.

Veeam completes acquisition of Securiti AI to build unified trusted data platform

Veeam completes its US$1.725 billion acquisition of Securiti AI to form a unified trusted data platform for secure and scalable AI adoption.

Related Articles

Popular Categories