Feiniu NAS Devices Hit in Massive Netdragon Botnet Attack Exploiting Unpatched Vulnerabilities
ID: effc9375-66a6-57a8-b439-1d55d2bcb94e
STIX ID: report--effc9375-66a6-57a8-b439-1d55d2bcb94e
Feed Name: GBHackers
A Netdragon botnet campaign is actively exploiting unpatched Feiniu fnOS NAS devices to install an HTTP backdoor (initially on port 57132, later 57199), deploy kernel modules and systemd services for persistence, erase logs and recovery mechanisms, and enlist over 1,000 devices into DDoS operations. The report includes technical details on handshake/encryption (XOR + ChaCha20), C2 infrastructure (domains, 45.95.*.* IP range, ports 3489/5098/6608/7489), file paths and binaries modified or created, and observed destructive actions (deletion of rsa_private_key.pem, tampering with update domains), plus telemetry and mitigation challenges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
