logo

Malware botnets exploit outdated D-Link routers in recent attacks

ID: 357f1c79-df99-5112-916b-3edae59e46d7

STIX ID: report--357f1c79-df99-5112-916b-3edae59e46d7

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-29

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Two IoT-focused botnets—Ficora (a Mirai-derived variant) and Capsaicin (a Kaiten-derived variant attributed to Keksec)—are actively exploiting known vulnerabilities in end-of-life or outdated D-Link routers (including CVE-2015-2051, CVE-2019-10891, CVE-2022-37056, CVE-2024-33112) to gain access, deploy multi-architecture payloads, brute-force additional devices, disable competing malware, exfiltrate host data, and conduct large-scale DDoS campaigns; Ficora shows a broad geographic footprint (notably Japan and the US) while Capsaicin had a short, intense surge focused on East Asia. Recommended mitigations include updating or replacing EOL devices, applying firmware patches, changing default credentials, and disabling unnecessary remote management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.