logo

Feiniu NAS Devices Infected in Large-Scale Netdragon Botnet Attack Exploiting Unpatched Vulnerabilities

ID: 9e85fb12-5009-5d45-a832-d4286e9896f1

STIX ID: report--9e85fb12-5009-5d45-a832-d4286e9896f1

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A new campaign by the Netdragon botnet is actively targeting Feiniu (fnOS) NAS devices via undisclosed vulnerabilities, installing an HTTP backdoor and modular malware (loader + DDoS module) to conscript devices into large-scale DDoS attacks; the malware also implements strong persistence (systemd service and kernel module async_memcpys.ko), sabotages updates by rewriting hosts, deletes critical private keys (rsa_private_key.pem), and has infected roughly 1,500 devices across multiple countries, with recommended remediation steps including removing malicious nft/iptables rules, deleting the kernel module and dockers.service, restoring hosts, and monitoring port 57199.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.