Warning of a surge in activity associated with FICORA and Kaiten botnets
Dec. 27, 2024, 5:21 p.m.
Tags
External References
Description
FortiGuard Labs researchers observed increased activity from two botnets in late 2024: the Mirai variant 'FICORA' and the Kaiten variant 'CAPSAICIN'. Both target vulnerabilities in D-Link devices, particularly through the HNAP interface, allowing remote command execution. The FICORA botnet downloads and executes a shell script to infect Linux systems, while CAPSAICIN uses a downloader script to target various Linux architectures. FICORA includes DDoS capabilities using multiple protocols. CAPSAICIN appears to be a variant of Keksec group botnets. The attacks exploit vulnerabilities that were patched years ago, highlighting the importance of regular device updates and monitoring.
Date
Published: Dec. 27, 2024, 3:52 p.m.
Created: Dec. 27, 2024, 3:52 p.m.
Modified: Dec. 27, 2024, 5:21 p.m.
Attack Patterns
CAPSAICIN
FICORA
T1571
T1059.004
T1095
T1106
T1190
T1072
CVE-2022-37056
CVE-2019-10891
CVE-2024-33112
CVE-2015-2051