Feiniu NAS Devices Infected in Large-Scale Netdragon Botnet Attack Exploiting Unpatched Vulnerabilities
ID: 9e85fb12-5009-5d45-a832-d4286e9896f1
STIX ID: report--9e85fb12-5009-5d45-a832-d4286e9896f1
Feed Name: cybersecurityNews.com
A new campaign by the Netdragon botnet is actively targeting Feiniu (fnOS) NAS devices via undisclosed vulnerabilities, installing an HTTP backdoor and modular malware (loader + DDoS module) to conscript devices into large-scale DDoS attacks; the malware also implements strong persistence (systemd service and kernel module async_memcpys.ko), sabotages updates by rewriting hosts, deletes critical private keys (rsa_private_key.pem), and has infected roughly 1,500 devices across multiple countries, with recommended remediation steps including removing malicious nft/iptables rules, deleting the kernel module and dockers.service, restoring hosts, and monitoring port 57199.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
