As long as there is a network at home, there will be a router, but once most people install it, they will almost forget about its existence unless they find that the network is abnormal and the router is broken. Therefore, you will not update or replace it regularly like your mobile phone or computer. Recently, security personnel have discovered that malware is using D-Link routers running outdated firmware to build botnets, and the amount of activity is not small.

Security researchers discover malware exploiting outdated D-Link routers to build botnet
The two botnets tracked by security personnel, named “Ficora” and “Capsaicin,” mainly exploit outdated D-Link router activities. The target models include popular D-Link devices used by individuals and organizations, including DIR-645, DIR-806, GO-RT-AC750, and DIR-845L. Ficora has a wide geographical presence, with some concentrated in Japan and the United States. Capsaicin appears to primarily target devices from East Asian countries, with activity increasing significantly in just two days starting on October 21st.

During the initial access phase, the two malware exploited known vulnerabilities CVE-2015-2051, CVE-2019-10891, CVE-2022-37056 and CVE-2024-33112. Once a device is compromised, the attacker exploits a vulnerability in the D-Link management interface (HNAP) and executes malicious commands through the GetDeviceSettings operation. The constructed botnet can steal data and execute shell scripts, and the attackers appear to be invading for DDoS purposes.

Ficora is a new variant of the Mirai botnet, according to security agency Telemetry data from Fortinet, the botnet showed random targeting and two significant spikes in activity during October and November. After gaining initial access to the D-Link device, Ficora uses a shell script named “multi” to download and execute its payload through various methods including wget, curl, ftpget, and tftp.

Capsaicin, a variant of the Kaiten botnet, was only observed active in a series of attacks between October 21 and 22.Telemetry data from Fortinet It shows that its main target is East Asian countries and regions. Infected via a downloader script, the malware actively looks for other botnet payloads active on the same host to deactivate them.

The most direct way to prevent routers and other IoT devices from becoming part of a botnet is to ensure that they are updated and running the latest version of firmware to block and patch known vulnerabilities. If your device has reached the end of its life and has stopped receiving security updates, it may be a good idea to get a new device. In addition, you should replace the default administrator account password with a unique and strong password, and disable remote access when not needed.
Source: KOCPC Chinese