• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Security researchers discover malware exploiting outdated D-Link routers to build botnet

Security researchers discover malware exploiting outdated D-Link routers to build botnet

Claire by Claire
December 30, 2024 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

As long as there is a network at home, there will be a router, but once most people install it, they will almost forget about its existence unless they find that the network is abnormal and the router is broken. Therefore, you will not update or replace it regularly like your mobile phone or computer. Recently, security personnel have discovered that malware is using D-Link routers running outdated firmware to build botnets, and the amount of activity is not small.

識別虛假病毒感染、安全警告的 12 個小技巧 - 電腦王阿達

Security researchers discover malware exploiting outdated D-Link routers to build botnet

The two botnets tracked by security personnel, named “Ficora” and “Capsaicin,” mainly exploit outdated D-Link router activities. The target models include popular D-Link devices used by individuals and organizations, including DIR-645, DIR-806, GO-RT-AC750, and DIR-845L. Ficora has a wide geographical presence, with some concentrated in Japan and the United States. Capsaicin appears to primarily target devices from East Asian countries, with activity increasing significantly in just two days starting on October 21st.

During the initial access phase, the two malware exploited known vulnerabilities CVE-2015-2051, CVE-2019-10891, CVE-2022-37056 and CVE-2024-33112. Once a device is compromised, the attacker exploits a vulnerability in the D-Link management interface (HNAP) and executes malicious commands through the GetDeviceSettings operation. The constructed botnet can steal data and execute shell scripts, and the attackers appear to be invading for DDoS purposes.

Microsoft 揭露「Adrozek」惡意軟體,Chrome、Firefox 跟 Edge 都是它的挾持目標 - 電腦王阿達

Ficora is a new variant of the Mirai botnet, according to security agency Telemetry data from Fortinet, the botnet showed random targeting and two significant spikes in activity during October and November. After gaining initial access to the D-Link device, Ficora uses a shell script named “multi” to download and execute its payload through various methods including wget, curl, ftpget, and tftp.

Capsaicin, a variant of the Kaiten botnet, was only observed active in a series of attacks between October 21 and 22.Telemetry data from Fortinet It shows that its main target is East Asian countries and regions. Infected via a downloader script, the malware actively looks for other botnet payloads active on the same host to deactivate them.

The most direct way to prevent routers and other IoT devices from becoming part of a botnet is to ensure that they are updated and running the latest version of firmware to block and patch known vulnerabilities. If your device has reached the end of its life and has stopped receiving security updates, it may be a good idea to get a new device. In addition, you should replace the default administrator account password with a unique and strong password, and disable remote access when not needed.

 

Source: KOCPC Chinese

Tags: D-LinkInternet securitymalware

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology