EwDoor was a botnet first observed in October 2021 exploiting the command-injection flaw CVE-2017-6079 on internet-exposed, unpatched EdgeMarc Enterprise Session Border Controllers (ESBCs) associated with AT&T customers. Qihoo 360 Netlab counted about 5,700 active U.S. victim IPs in a three-hour observation window. A separate set of roughly 100,000 IPs shared a certificate, but that did not establish that all of them were infected. The incident is a historical observation, not evidence of an active EwDoor campaign in 2026.
What EwDoor targeted
EwDoor is the name Qihoo 360 Netlab gave a botnet targeting Edgewater Networks products. The affected equipment was EdgeMarc Enterprise Session Border Controller hardware in AT&T-linked environments. A session border controller sits at the boundary of voice-over-IP (VoIP) networks, helping manage and secure communications between networks. Ribbon product documentation identifies the EdgeMarc 7000 family, including the 7300/7301 and 7400 platforms, as ESBCs.
Netlab first observed attacks on October 27, 2021. The attackers used CVE-2017-6079, a command-injection vulnerability, to compromise internet-exposed appliances that had not been patched. The reporting connects the campaign to EdgeMarc devices associated with AT&T customers; it does not establish that every EdgeMarc appliance or every AT&T customer was affected.
How many devices were infected?
Netlab observed about 5,700 active victim IP addresses during a three-hour window. It reported that those IPs were in the United States and associated with AT&T’s AS7018 network. This is a time-bounded measurement from 2021, not a confirmed count of every device ever compromised.
#1 Best Overall
- Quad Core J3710 Processor: F3 firewall hardware with Pentium J3710 Processor, 4 Cores 4 Threads, 2M Cache, up to 2.64 GHz, TDP 6.5 W. Compatible with OPNsense, Linux, ESXi, Proxmox
- 4 x i225V 2.5GbE LAN: J3710 mini pc with 4 x i225V 2500Mbps LAN, can monitor network data, improve network security, powerful and widely used
- DDR3 RAM mSATA Slot: J3710 firewall pc with 1 x DDR3L SO-DIMM memory, 1 x mSATA SSD slot, 1 x SATA 3.0 slot(SATA Cable included), 1 x Mini-PCIe Slot
- HD DP Dual Display: Micro firewall appliance J3710 integrated HD Graphics, HD + DP dual display interfaces improve work efficiency
- Fanless Mini Size: Firewall appliance J3710 with aluminium alloy body, fanless quiet running without noise. Size only 11 x 10 x 3.5 cm
Netlab also identified roughly 100,000 IP addresses using the same SSL certificate. It cautioned that the certificate match indicated possible exposure, not confirmed infection. The larger number should therefore not be described as the number of EwDoor victims. BleepingComputer independently summarized the approximately 5,700-device observation and the CVE-2017-6079 exploit path.
What the malware could do
Netlab’s captured samples supported several remote-control and attack functions:
Rank #2
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
- Launch distributed denial-of-service (DDoS) attacks.
- Open a reverse shell and execute arbitrary commands.
- Scan ports.
- Manage files and update itself.
Netlab assessed that DDoS attacks and collection of sensitive information, potentially including call logs, were likely objectives because the targets handled voice and telecom traffic. That was an analyst assessment of likely intent, not confirmation that call logs were stolen or that every capability was used in each infection.
How the campaign changed in 2021
| Date | Reported development |
|---|---|
| October 27, 2021 | Netlab’s Botmon system observed attacks using CVE-2017-6079. Researchers named the malware EwDoor for its Edgewater targeting and backdoor functionality. |
| November 8, 2021 | Netlab observed a command-and-control redesign that used BitTorrent trackers after problems with the original command-and-control infrastructure. |
| November 15–20, 2021 | Netlab recorded further updates, including changes to tracker use and behavior intended to confront or evade sandboxes. |
The Record reported that AT&T “had taken steps to mitigate” the botnet after investigating the incident. That historical report does not, by itself, establish the present security or support status of any particular appliance.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- ✅【Professional Firewall PC MGSRN305】MOGINSOK Firewall Appliance Mini PC--MGSRN100, with Intel Processor Alder Lake-N100 (4C/4T,up to 3.4GHz) processor Intel UHD Graphics TDP only 6W, supported AES-NI With HDMI 2.1+DP 1.4 Support Dual 4K@60Hz Display, a fanless & silent professional firewall router pc with multi-functions like AES-NI, ESXI, Watchdog, Auto power on, RTC, PXE boot, Wake-on-LAN etc. bring you a secured and encrypted network environment.
- ✅【DDR5 Ram & PCIE 3.0 SSD】MOGINSOK Micro Firewall Appliance MGSRN100 with Barebone No Ram(1x Single slot support maximum 32GB DDR5 4800MHz) and No SSD(1*M.2 PICE 3.0 slot) configurations, you can install your own ram and ssd for DIY depends on your application.
- ✅【Professional OS installed】MGSRN305 Pre-installed pfsense plus 23.0X OS and you can install OPNsense, OpenWrt, Unbutun, windows 10 or 11 and other popular open-source software solutions on this Firewall Router. Which you can use it as an Firewall, Netgate, Softrouting, NAS, Firewall, ESXI, PVEvirtualization platform(support VT-X,VT-D).
- ✅【Intel I226 2.5GbE Network Card】This Firewall Router equipped with 4*Intel I226 Network card maximum up to 2.5GbE, bring you more faster and professional network usage(some system suppliers maybe have not released compatible driver to match yet, suggest to install newest version of following systems: pfSense 23.01(or 2.7.0), Untangle( via virtual machine) OPNsense 22.1, OpenWrt, ROS7, ESXI, Proxmox, CentOS etc).
- ✅【Quality With Warranty】If you have any questions on MOGINSOK Firewall Appliance MGSRN100, feel free to contact us(if you want to get the latest bios update, you can send us message via Amazon). We offered 12 Months warranty for it and WE'LL REPLY YOUR Questions within 12 hours(during Workdays).
How to check and protect an EdgeMarc ESBC
For an organization that operates EdgeMarc or other ESBC equipment, prioritize identifying exposed appliances, assessing signs of compromise, and restoring the device to a vendor-supported state. CISA’s network-device guidance advises reviewing device logs and configurations and upgrading unsupported devices to vendor-supported versions that receive security updates.
- Inventory internet exposure. Identify each EdgeMarc/ESBC appliance reachable from the internet. Record its model, firmware version, business owner, network location, and vendor support status. Include appliances managed by a service provider or another team so they are not missed.
- Review configuration and activity. Examine appliance logs and configuration, startup files, scheduled tasks such as cron entries, outbound DNS and TLS activity, and records of unexpected command execution. Look for unexplained changes or connections that warrant investigation; the available reporting does not provide a complete indicator-of-compromise list.
- Isolate suspected devices. If an appliance appears compromised, restrict its access to production voice and data networks while preserving logs and other evidence for incident response. Coordinate isolation with voice and network operators to manage service impact.
- Patch or replace. Apply security updates supported by the vendor for the exact model and firmware. If the device is unsupported or cannot receive security updates, plan to replace or upgrade it rather than leave it exposed. Confirm current model support and applicable updates with the vendor; historical reporting does not establish which legacy models remain supported today.
- Validate connected services. After remediation, check downstream VoIP, routing, and authentication systems for unexpected changes or access. An SBC is a trusted network boundary, so its compromise may matter beyond the appliance itself.
Choosing a replacement or remediation path
For a replacement ESBC or a longer-term edge-security plan, compare options against the environment’s operational needs rather than selecting a generic router or consumer antivirus product. Useful criteria include:
- How long the vendor will support the model and deliver security updates.
- Whether internet exposure can be limited to required services and trusted sources.
- What logs and detection capabilities are available, and how they can be monitored.
- Compatibility with the organization’s VoIP and SIP systems.
- Failover and resilience requirements for voice services.
- Migration effort, including configuration changes and service-provider coordination.
The EwDoor observations describe activity in October and November 2021. They do not establish ongoing spread in 2026, the current support status of a particular EdgeMarc model, or whether a specific appliance is compromised. Those questions require a current device inventory and confirmation from the vendor or the organization responsible for the equipment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

