Are Legacy Vulnerabilities in D-Link Routers Fueling New Botnet Attacks?

Recent cyberattacks targeting vulnerable D-Link routers have raised concerns within the cybersecurity community, as documented vulnerabilities originally discovered years ago are being actively exploited once again. The resurgence of these attacks has been attributed to two distinct botnets: a Mirai variant named FICORA and a Kaiten variant known as CAPSAICIN, which leverage these weaknesses to cause significant disruption.

Exploited Vulnerabilities Persist Despite Patches

Cybersecurity researchers have highlighted that these botnets take advantage of long-known vulnerabilities in D-Link routers, some of which date back nearly a decade. Several critical CVEs, including CVE-2015-2051, CVE-2019-10891, CVE-2022-37056, and CVE-2024-33112, exploit the Home Network Administration Protocol (HNAP) interface, providing a gateway for attackers despite patches having been available for years. This enduring issue underscores the ongoing risk posed by legacy devices that have not been properly updated.

Distinct Targets and Attack Methods

The FICORA botnet casts a wide net, targeting countries globally with its sophisticated attack mechanisms. Once a vulnerable router is compromised, FICORA deploys a downloader shell script from a remote server, which retrieves the primary payload suitable for various Linux architectures using commands such as wget, ftpget, curl, and tftp. Furthermore, this botnet incorporates a brute-force attack function that utilizes a hard-coded list of usernames and passwords, enhancing its ability to conduct distributed denial-of-service (DDoS) attacks across UDP, TCP, and DNS protocols.

On the other hand, the CAPSAICIN botnet focuses its efforts on East Asia, especially Japan and Taiwan, with peak activity observed between October 21-22, 2024. This variant employs a different IP address for payload downloads and ensures compatibility with diverse Linux architectures. Notably, CAPSAICIN eliminates other known botnet processes to become the dominant botnet on the affected device, creating a connection with its command-and-control server to forward the victim’s operating system information and assigned nickname, awaiting further instructions.

Commands and Techniques Utilized by CAPSAICIN

CAPSAICIN stands out with its versatility in operations, capable of executing various commands such as obtaining IP addresses, deleting command histories, initiating proxies, changing nicknames, downloading files, and running shell commands. Its DDoS attack capabilities are notable, with specific attacks including HTTP flooding, TCP connection flooding, DNS amplification, and BlackNurse attacks. This breadth of functionality makes CAPSAICIN a formidable threat to affected networks.

The Continued Threat of Legacy Vulnerabilities

Recent cyberattacks targeting vulnerable D-Link routers have triggered alarm bells within the cybersecurity community. These routers are being actively exploited through documented vulnerabilities that were originally discovered years ago. The reemergence of these attacks has been attributed to the activities of two distinct botnets: a Mirai variant known as FICORA and a Kaiten variant called CAPSAICIN. These malicious networks leverage longstanding weaknesses to cause considerable disruption, making it crucial for users to be aware of potential risks.

The Mirai botnet, infamous for its role in significant past cyberattacks, continues to evolve, now adopting the FICORA variant to exploit these D-Link router vulnerabilities. Similarly, the Kaiten botnet’s CAPSAICIN variant has been recognized for effectively capitalizing on the same weaknesses. This resurgence emphasizes the importance of regular updates and patches for network devices, as outdated firmware remains a significant security risk. Cybersecurity experts urge users to ensure their devices are running the latest firmware versions to mitigate these threats.

Explore more

How to Scale B2B Lead Generation on LinkedIn Successfully?

The landscape of professional networking has undergone a radical transformation, moving away from simple connection requests toward a centralized ecosystem for business growth. In the current market, the platform serves as the primary conduit for high-value transactions, where digital presence directly correlates with market share. Organizations that treat this space as a static directory find themselves falling behind competitors who

Ukraine’s E-Commerce Tax Bill Faces Critical Hurdles for EU Integration

The rapid evolution of the digital marketplace has forced governments worldwide to rethink fiscal boundaries, yet Ukraine’s attempt to legislate this boundary through Draft Law No. 15112-d reveals a profound friction between wartime survival and the strict requirements of European integration. As the country navigates its path into the European Union, the Verkhovna Rada faces a daunting task: creating a

Vietnam Strengthens Legal Compliance for E-commerce Growth

Behind the vibrant glow of smartphone screens across Hanoi and Ho Chi Minh City, a massive digital transformation is quietly reshaping the economic identity of the nation through an unprecedented surge in online transactions. This shift represents more than just a change in shopping habits; it signifies a structural evolution where the virtual marketplace is no longer an alternative to

How Agentic AI Is Transforming the B2B Buying Journey

Across the global enterprise landscape, a profound transformation is quietly unfolding as autonomous software agents begin to dominate the intricate process of corporate procurement and vendor selection. This evolution represents a departure from the days when human curiosity drove the early stages of the sales cycle. Today, the initial heavy lifting of market research, technical vetting, and vendor comparison is

10 Best Free or Low-Cost CRM Tools for Small Businesses

Many inexpensive CRM options provide unlimited file storage, making it easier for service-based businesses to manage client contracts and project documents. In the current landscape of 2026, small and midsize enterprises are increasingly moving away from antiquated manual tracking in favor of centralized digital hubs that unify customer interactions. The competitive pressure to deliver personalized experiences has made customer relationship