Malware botnets exploit outdated D-Link routers in recent attacks
ID: 357f1c79-df99-5112-916b-3edae59e46d7
STIX ID: report--357f1c79-df99-5112-916b-3edae59e46d7
Feed Name: Bleeping Computer
Two IoT-focused botnets—Ficora (a Mirai-derived variant) and Capsaicin (a Kaiten-derived variant attributed to Keksec)—are actively exploiting known vulnerabilities in end-of-life or outdated D-Link routers (including CVE-2015-2051, CVE-2019-10891, CVE-2022-37056, CVE-2024-33112) to gain access, deploy multi-architecture payloads, brute-force additional devices, disable competing malware, exfiltrate host data, and conduct large-scale DDoS campaigns; Ficora shows a broad geographic footprint (notably Japan and the US) while Capsaicin had a short, intense surge focused on East Asia. Recommended mitigations include updating or replacing EOL devices, applying firmware patches, changing default credentials, and disabling unnecessary remote management interfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
