Table of Contents
Researcher from NewSky Security recently discovered a hacker nicknamed Anarchy, only 24 hours to build a botnet from 18, 000 Huawei router devices.
Hackers Took Control of 18, 000 Huawei Router Devices in Just One Day Overview
- What is a botnet, who does it use to attack, and how can you prevent botnet?
Immediately, other security vendors Rapid7 and Qihoo 360 Netlab quickly joined in and found that scanning of Huawei devices suddenly spiked.

The reason for this increase is that hackers conduct scans to search for vulnerable routers before the critical security vulnerability CVE-2017-17215, which can be exploited through port 37215. Hackers start perform this scan on July 18.
With this method, hackers can send malicious packets, launch attacks on Huawei routers and execute code remotely. The attacker can then control and add these devices to the botnet.
The purpose of the hacker is to create "the worst botnet in the city". This botnet may be used in targeted attacks or may be leased to bad guys to accomplish the attack.
Not only that, Anarchy also said he also intends to start scanning Realtek router router CVE-2014-8361, to control more devices.
See more:
- Warning: Bkav detected more than 700, 000 computers in Vietnam infected with virtual money digging virus that slowed down the computer
- Half a million computers in Vietnam suffer from dangerous spyware
- Warning of new malware appear like Wannacry, capable of deleting Vietnamese percussion on computer
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does hackers Took Control of 18, 000 Huawei Router Devices in Just One Day matter?
Researcher from NewSky Security recently discovered a hacker nicknamed Anarchy, only 24 hours to build a botnet from 18, 000 Huawei router devices.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.