针对飞牛 NAS 的僵尸网络Netdragon 快速分析
ID: 192cabef-d50e-57db-82b0-e2bd1e4cb54d
STIX ID: report--192cabef-d50e-57db-82b0-e2bd1e4cb54d
Feed Name: QiAnXin XLab
Netdragon is a modular malware family targeting fnOS NAS devices, actively observed since October 2024 and estimated to have infected ~1,000–1,500 devices. The malware installs an HTTP backdoor, supports remote command execution and DDoS operations, uses dual user/kernel persistence (systemd service and kernel module), performs aggressive anti-analysis and remediation bypasses (hosts hijacking, deleting iptables/nft rules, clearing logs), and rotates C2 infrastructure and packing to resist cleanup; IoCs (domains, IPs, file hashes) and protocol details are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
