Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Feiniu NAS Devices Hit in Massive Netdragon Botnet Attack Exploiting Unpatched Vulnerabilities

## Cybersecurity: Netdragon Botnet Attack on Feiniu fnOS NAS Devices

Cybersecurity: Netdragon Botnet Attack on Feiniu fnOS NAS Devices

Feiniu fnOS network-attached storage (NAS) devices have been integrated into a substantial Netdragon botnet due to the exploitation of unresolved vulnerabilities. This breach has transformed home and small-business storage systems into tools for executing DDoS attacks.

The malware establishes an HTTP backdoor on port 57132, which permits attackers to execute arbitrary system commands remotely via specifically crafted GET requests to the /api path.

Analysis of traffic fingerprints and asset-mapping data revealed signs of compromise on over 1,000 IP addresses, all linked to Feiniu devices, with no other vendors affected.

Researchers confirmed the presence of malicious code on Internet-exposed Feiniu NAS devices running fnOS, connecting the samples to the Netdragon malware family first identified in October 2024.

By late January, command and control (C2) telemetry indicated the botnet had expanded to approximately 1,500 infected Feiniu NAS nodes, with over 1,100 bots online concurrently in one control-panel snapshot.

This breach has transformed home and small-business storage systems into tools for executing DDoS attacks.
John Mason · Thehackingpost

Technical Measures Employed by Malware

The loader component erases extensive log directories to remove traces of intrusion and lateral activity. It modifies /etc/hosts to redirect Feiniu’s update domains, effectively blocking firmware updates and security patches. Recovery-related services are terminated, and update binaries are deleted, complicating repair or rollback efforts. Persistence is achieved through systemd services and kernel modules, ensuring the malware remains post-reboot.

For persistence, the malware appends a startup command to system_startup.sh , downloading and executing a second-stage payload. It registers systemd units to auto-start and introduces new kernel modules and services to evade cleanup scripts.

Communication with the C2 infrastructure is secured with layered XOR and ChaCha20 encryption, using a handshake step for verification. The botnet receives attack instructions via various channels, launching DDoS campaigns against organizations across several countries and sectors.

As defenders published detection rules and Feiniu distributed cleanup scripts, Netdragon operators released new builds that restore outbound access to C2 servers, further complicating defensive measures.

Advertisement

The malware has moved its HTTP backdoor to a new port and introduced dynamic key packing to hinder static signatures and reverse engineering.

On February 1, operators commanded bots to delete critical files on Feiniu NAS systems, potentially causing data loss. Feiniu users report difficulties in applying firmware upgrades or security tools, leaving devices compromised and perpetuating the botnet.

Continued efforts are necessary to address fnOS vulnerabilities and provide effective remediation paths to mitigate the ongoing threat posed by the Netdragon botnet.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories