Computer Security News

D-Link Routers Under Attack – Botnet Exploiting Devices to Gain Full Remote Control

A surge in cyberattacks leveraging legacy vulnerabilities in D-Link routers has been detected, with two botnets, FICORA and CAPSAICIN, actively exploiting these weaknesses.

Researchers at Fortinet’s FortiGuard Labs observed a spike in activity from these botnets during October and November 2024, highlighting the persistent threat posed by outdated and unpatched networking devices.

Exploitation of Decade-Old Vulnerabilities

The botnets exploit flaws in the Home Network Administration Protocol (HNAP) interface of D-Link routers, enabling remote attackers to execute malicious commands.

These vulnerabilities, tracked under CVE identifiers such as CVE-2015-2051, CVE-2019-10891, CVE-2022-37056, and CVE-2024-33112, were disclosed years ago but remain a significant risk due to the widespread use of unpatched devices.

Despite patches being available for many of these flaws, the continued reliance on legacy hardware has created an opportunity for cybercriminals to deploy malware at scale.

Exploitation Timeline

2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide

The FICORA botnet, a variant of the infamous Mirai malware, uses brute-force techniques to compromise devices and employs advanced encryption (ChaCha20) to conceal its configuration and command-and-control (C2) details. It is capable of launching distributed denial-of-service (DDoS) attacks using multiple protocols, including UDP and TCP.

FICORA botnet

Meanwhile, the Kaiten-based CAPSAICIN botnet prioritizes rapid deployment and eliminates competing malware on infected devices to maintain control.

CAPSAICIN botnet

FortiGuard Labs identified that the FICORA botnet was propagated from servers located in the Netherlands (e.g., IPs 185[.]191[.]126[.]213 and 185[.]191[.]126[.]248). The attacks were global in nature, suggesting they were not targeted but opportunistic campaigns aimed at exploiting any vulnerable device.

Both botnets underscore the dangers posed by outdated network hardware. While the vulnerabilities have been known for years, many organizations have failed to implement patches or replace end-of-life devices. This negligence has allowed attackers to repeatedly exploit these weaknesses.

Experts strongly advise enterprises and individuals to take proactive measures to mitigate these risks:

  • Regular Updates: Ensure that all routers and network devices are running the latest firmware versions.
  • Device Replacement: Replace end-of-life (EOL) hardware that no longer receives security updates.
  • Network Monitoring: Implement comprehensive monitoring solutions to detect unusual traffic patterns indicative of botnet activity.
  • Access Restrictions: Disable remote management features unless absolutely necessary and use strong, unique passwords for device access.

Organizations must prioritize updating or replacing vulnerable devices to prevent becoming unwitting participants in botnet-driven cybercrime campaigns.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago