Several dozen Imperva Incapsula customers were targeted by a DDoS botnet comprised of tens of thousands of hijacked SOHO routers. The attackers leveraged remotely accessibility to the SohO routers via HTTP and SSH on their default ports in order to compromise the network devices. 85 percent of all compromised routers are located in Thailand and Brazil, while the majority of the C2s are in the US (21%) and China (73%) The researchers recorded malicious traffic originated from more than 40,000 IP addresses belonging to nearly 1,600 ISPs across 109 countries.”]
Source: https://securityaffairs.co/wordpress/36769/cyber-crime/botnet-soho-routers.html

