{
  "name": "Warning of a surge in activity associated with FICORA and Kaiten botnets",
  "slug": "warning-of-a-surge-in-activity-associated-with-ficora-and-kaiten-botnets",
  "description": "FortiGuard Labs researchers observed increased activity from two botnets in late 2024: the Mirai variant 'FICORA' and the Kaiten variant 'CAPSAICIN'. Both target vulnerabilities in D-Link devices, particularly through the HNAP interface, allowing remote command execution. The FICORA botnet downloads and executes a shell script to infect Linux systems, while CAPSAICIN uses a downloader script to target various Linux architectures. FICORA includes DDoS capabilities using multiple protocols. CAPSAICIN appears to be a variant of Keksec group botnets. The attacks exploit vulnerabilities that were patched years ago, highlighting the importance of regular device updates and monitoring.",
  "published": "2024-12-27T14:52:44+00:00",
  "created_at": "2024-12-27T14:52:44+00:00",
  "modified_at": "2024-12-27T16:21:42+00:00",
  "created_at_opencti": "2024-12-27T14:52:44+00:00",
  "author": "",
  "confidence": null,
  "report_types": [],
  "labels": [],
  "tags": [
    "2024-12-27",
    "CVE-2015-2051",
    "CVE-2019-10891",
    "CVE-2022-37056",
    "CVE-2024-33112",
    "botnet",
    "capsaicin",
    "d-link",
    "ficora",
    "kaiten",
    "linux",
    "mirai"
  ],
  "related_entities": {
    "observables": [
      {
        "id": "",
        "name": "87.10.220.221"
      },
      {
        "id": "",
        "name": "192.110.247.46"
      }
    ],
    "malware": [
      {
        "id": "a03cae18-9845-46cf-b191-f79bdec737b0",
        "name": "CAPSAICIN",
        "slug": "capsaicin"
      },
      {
        "id": "927d5904-3ee7-49f5-90a2-47ca5a0f5153",
        "name": "FICORA",
        "slug": "ficora"
      }
    ],
    "attack_patterns": [
      {
        "id": "16e26db7-7376-40c1-b8a9-23d56c44f7ee",
        "name": "T1571"
      },
      {
        "id": "2e0c6db7-16a7-4bf6-992e-263474014fce",
        "name": "T1059.004"
      },
      {
        "id": "88fa397b-4cc9-42c0-b52d-4108f9630529",
        "name": "T1095"
      },
      {
        "id": "60972cf6-e90b-4600-af3c-13c468391d9c",
        "name": "T1106"
      },
      {
        "id": "6c8f8a40-2746-4a37-86bd-81e82afa6e62",
        "name": "T1190"
      },
      {
        "id": "6a495275-5433-4b64-90e5-18b9f07296da",
        "name": "T1072"
      }
    ],
    "vulnerabilities": [
      {
        "id": "",
        "name": "CVE-2022-37056"
      },
      {
        "id": "",
        "name": "CVE-2019-10891"
      },
      {
        "id": "",
        "name": "CVE-2024-33112"
      },
      {
        "id": "",
        "name": "CVE-2015-2051"
      }
    ]
  },
  "external_refs": [
    "https://securityaffairs.com/172373/uncategorized/surge-ficora-kaiten-botnets.html",
    "https://otx.alienvault.com/pulse/676ecd4c7f9f21eabaaec6fb"
  ]
}