logo

New "Goldoon" Botnet Targets D-Link Routers With Decade-Old Flaw

ID: 19583933-dfa3-51ce-87ad-7865c2abbadd

STIX ID: report--19583933-dfa3-51ce-87ad-7865c2abbadd

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-02

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers observed a previously unseen botnet called Goldoon actively exploiting CVE-2015-2051 (CVSS 9.8) in D-Link DIR-645 routers to install multi-architecture payloads that download the Goldoon malware, establish persistence, connect to C2 servers, and provide at least 27 DDoS flood methods and proxying capabilities; telemetry indicates a noticeable activity spike around April 9, 2024, and operators use compromised routers for anonymization and various criminal services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.