• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Security researchers discover malware exploiting outdated D-Link routers to build botnet

Security researchers discover malware exploiting outdated D-Link routers to build botnet

Claire by Claire
December 30, 2024 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

As long as there is a network at home, there will be a router, but once most people install it, they will almost forget about its existence unless they find that the network is abnormal and the router is broken. Therefore, you will not update or replace it regularly like your mobile phone or computer. Recently, security personnel have discovered that malware is using D-Link routers running outdated firmware to build botnets, and the amount of activity is not small.

識別虛假病毒感染、安全警告的 12 個小技巧 - 電腦王阿達

Security researchers discover malware exploiting outdated D-Link routers to build botnet

The two botnets tracked by security personnel, named “Ficora” and “Capsaicin,” mainly exploit outdated D-Link router activities. The target models include popular D-Link devices used by individuals and organizations, including DIR-645, DIR-806, GO-RT-AC750, and DIR-845L. Ficora has a wide geographical presence, with some concentrated in Japan and the United States. Capsaicin appears to primarily target devices from East Asian countries, with activity increasing significantly in just two days starting on October 21st.

During the initial access phase, the two malware exploited known vulnerabilities CVE-2015-2051, CVE-2019-10891, CVE-2022-37056 and CVE-2024-33112. Once a device is compromised, the attacker exploits a vulnerability in the D-Link management interface (HNAP) and executes malicious commands through the GetDeviceSettings operation. The constructed botnet can steal data and execute shell scripts, and the attackers appear to be invading for DDoS purposes.

Microsoft 揭露「Adrozek」惡意軟體,Chrome、Firefox 跟 Edge 都是它的挾持目標 - 電腦王阿達


Ficora is a new variant of the Mirai botnet, according to security agency Telemetry data from Fortinet, the botnet showed random targeting and two significant spikes in activity during October and November. After gaining initial access to the D-Link device, Ficora uses a shell script named “multi” to download and execute its payload through various methods including wget, curl, ftpget, and tftp.

Capsaicin, a variant of the Kaiten botnet, was only observed active in a series of attacks between October 21 and 22.Telemetry data from Fortinet It shows that its main target is East Asian countries and regions. Infected via a downloader script, the malware actively looks for other botnet payloads active on the same host to deactivate them.

The most direct way to prevent routers and other IoT devices from becoming part of a botnet is to ensure that they are updated and running the latest version of firmware to block and patch known vulnerabilities. If your device has reached the end of its life and has stopped receiving security updates, it may be a good idea to get a new device. In addition, you should replace the default administrator account password with a unique and strong password, and disable remote access when not needed.

 

Source: KOCPC Chinese

Tags: D-LinkInternet securitymalware

Recent Posts

  • Meta Muse Lands on Mac: Personal AI Agent Begins Operating Your Files, Messages, and Calendar (Muse for Mac)
  • First oMLX performance results for M5 Ultra Mac Studio leak: prefill speed 3-4x faster than M3 Ultra, data taken down after exposure.
  • After the iPhone 17, the frame material was changed back to aluminum alloy. Is it better than titanium?
  • The iPhone 18 Pro series, Apple Watch Series 12, Apple Watch Ultra 4, and AirPods 5 are now on sale—a first look, with warm “Burgundy Red” and striking “Glacier Blue.”
  • The battery replacement cost for the iPhone 18 Pro / Pro Max has gone up again! Compared with 5 years ago, the increase has doubled.

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology