Murdoc is a Mirai variant that Qualys reported targeting AVTECH cameras and Huawei HG532 routers in a campaign it observed starting in July 2024. The reported exploits are CVE-2024-7029 for AVTECH cameras and CVE-2017-17215 for Huawei HG532 routers. If you manage either device, check whether it is exposed, keep supported firmware current, and isolate or replace unsupported hardware.
What the Murdoc botnet targets
Qualys describes Murdoc as a Mirai malware family for Unix-like systems. Its January 2025 campaign analysis names AVTECH cameras and Huawei HG532 routers; it does not establish that every product from either manufacturer is affected.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
AVTECH AVM3455 3MP Motorized Bullet Network Camera | $388.00 | Buy on Amazon |
| 2 |
|
AV8365CO-HB 36 Megapixel SurroundVideo 360° IP Camera | $2,488.00 | Buy on Amazon |
The campaign report links the two device families to separate vulnerabilities. Censys describes CVE-2024-7029 as an unpatchable command-injection vulnerability affecting end-of-life AVTECH IP cameras. The available reporting does not provide a current list of affected firmware revisions, so owners should verify the exact model and support status rather than assume that a brand name alone indicates exposure.
| Device named in reports | Associated vulnerability | Reported qualification |
|---|---|---|
| AVTECH IP cameras | CVE-2024-7029 | Censys describes the issue as unpatchable on the affected end-of-life cameras; not every exposed AVTECH camera is necessarily vulnerable. |
| Huawei HG532 routers | CVE-2017-17215 | Qualys identifies this exploit in the campaign; the report does not establish that all Huawei routers are affected. |
How the reported campaign works
Qualys observed a chain involving executable and shell-script payloads. In its analysis, scripts were fetched using tools such as wget or ftpget, executed, and removed; command-and-control servers distributed the Murdoc variant. This is a description of observed activity, not proof that every compromised device follows precisely the same sequence.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Versatile: This product can be used for a variety of purposes, making it a practical choice.
- Durable Construction: Built to withstand regular use and wear, ensuring long-lasting performance.
- Compact Design: Featuring a space-saving and portable design for easy storage and transportation.
- User-Friendly: Intuitive controls and operation, making it accessible for users of all skill levels.
- Efficient Performance: Designed to deliver optimal results while minimizing energy consumption or resource usage.
Qualys said it analyzed more than 500 ELF and shell-script samples. A compromised device can be incorporated into a botnet used for distributed denial-of-service attacks, as summarized by SecurityWeek. That does not mean an owner can identify infection from a single symptom: unusual processes, events, or network traffic warrant investigation, but the reports do not supply a definitive consumer-facing diagnostic test.
What the reported counts do—and do not—show
The figures below are dated observations from different sources and collection methods. They are not interchangeable measures of total infections, and none establishes Murdoc prevalence in October 2026.
| Figure | Source and date | What was counted |
|---|---|---|
| More than 1,300 | Qualys, January 2025 campaign report | Active campaign IPs reported by Qualys. |
| More than 100 | Qualys, January 2025 campaign report | Distinct sets of command-and-control servers identified. |
| 221 | Censys, scans reported as of January 22, 2025 | Hosts Censys identified as Murdoc-infected in its scans. Censys cautioned that higher reports may include truncated hosts or unusual pseudo-services rather than genuine hosts. |
| More than 36,182 | Censys, 2025 | Exposed AVTECH cameras; Censys explicitly noted that not all were necessarily vulnerable to CVE-2024-7029. |
| 7,805 in 2024 Q3; 3,215 in 2025 Q1 | HKCERT, 2025 Q1 report | Botnet events, not Murdoc infections. HKCERT also noted Mirai activity targeting AVTECH cameras and Huawei HG532 routers. |
Qualys reported Malaysia as the largest concentration of affected IP addresses in its observation, followed by Thailand, Mexico, and Indonesia. Those are campaign observations published in January 2025, not a current geographic distribution.
What device owners and administrators should do
Check exposure and support status
- Identify the exact camera or router model and whether it is reachable from the public internet. The campaign reports name AVTECH cameras and Huawei HG532 routers, not every device made by those companies.
- For supported equipment, install the vendor’s current firmware and security updates. The cited reports do not provide a current affected-firmware list or establish a patch for every named device.
- For discontinued AVTECH cameras that no longer receive security updates, Censys recommends isolating them from external networks or replacing them with supported hardware.
Watch for suspicious activity
Qualys recommends monitoring processes, events, and network traffic associated with untrusted binaries or scripts. Treat unexpected script execution or unusual outbound connections as reasons to investigate through your normal device and network-management procedures; the reports do not validate a particular cleanup utility or establish that rebooting removes an infection.
Recommended Free Tools
Rank #2
- 360° Panoramic View: Capture every angle with this 36MP SurroundVideo IP camera's immersive 360° field of view.
- Crystal Clear Imaging: Enjoy stunningly detailed videos and images with the camera's ultra-high 36 megapixel resolution.
- Robust Construction: Built to withstand harsh environments with an IP66 weatherproof rating and IK10 impact resistance.
- Smart Functionality: Advanced motion detection, audio analytics, and night vision capabilities enhance security monitoring.
- Flexible Integration: Compatible with major VMS platforms and ONVIF protocols for seamless system integration.
Handle scripts cautiously
Do not run scripts from unknown or untrusted sources on network devices or administrative systems. The campaign analysis describes scripts being used to fetch and execute payloads, which makes source verification and cautious handling relevant safeguards.
Retire unsupported hardware deliberately
If an AVTECH camera is end-of-life and cannot be secured through supported updates, isolate it from external networks or replace it with a supported IP security camera. Owners retiring an obsolete HG532 may likewise consider a supported router, but the cited sources do not recommend particular replacement models or establish compatibility with a reader’s ISP or installation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is not established
The January 2025 reports do not establish the current number of Murdoc infections, whether a specific device is infected, a complete list of affected firmware revisions, or suitable replacement models. Exposure also depends on the exact device and its network configuration; a count of exposed cameras should not be read as a count of vulnerable or compromised cameras.
Sources: Qualys campaign analysis; Censys campaign tracking; SecurityWeek report; HKCERT 2025 Q1 Security Watch Report.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

