FICORA, CAPSAICIN Botnets Exploit Old D-Link Router Flaws for DDoS Attacks
ID: f4cc8630-1729-5950-9a70-106b2a9a395f
STIX ID: report--f4cc8630-1729-5950-9a70-106b2a9a395f
Feed Name: HackRead
FortiGuard Labs observed a surge in two Mirai/Kaiten-derived botnets, FICORA and CAPSAICIN, in Oct–Nov 2024 that exploit long-standing D-Link HNAP vulnerabilities (including CVE-2015-2051, CVE-2019-10891, CVE-2022-37056, CVE-2024-33112) to deliver multi-architecture Linux malware via downloader scripts (‘multi’, ‘bins.sh’); the malware uses ChaCha20 for configuration, kills competing malware processes, connects to C2, and performs UDP/TCP/DNS DDoS attacks — mitigation recommended: firmware/kernel updates and enhanced network monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
