logo

FICORA, CAPSAICIN Botnets Exploit Old D-Link Router Flaws for DDoS Attacks

ID: f4cc8630-1729-5950-9a70-106b2a9a395f

STIX ID: report--f4cc8630-1729-5950-9a70-106b2a9a395f

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-12-28

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

FortiGuard Labs observed a surge in two Mirai/Kaiten-derived botnets, FICORA and CAPSAICIN, in Oct–Nov 2024 that exploit long-standing D-Link HNAP vulnerabilities (including CVE-2015-2051, CVE-2019-10891, CVE-2022-37056, CVE-2024-33112) to deliver multi-architecture Linux malware via downloader scripts (‘multi’, ‘bins.sh’); the malware uses ChaCha20 for configuration, kills competing malware processes, connects to C2, and performs UDP/TCP/DNS DDoS attacks — mitigation recommended: firmware/kernel updates and enhanced network monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.