Feiniu NAS Devices Infected in Large-Scale Netdragon Botnet Attack Exploiting Unpatched Vulnerabilities
Recent reports have identified a significant security breach involving Feiniu (fnOS) Network Attached Storage (NAS) devices. These devices are being compromised by the Netdragon botnet, exploiting unpatched vulnerabilities within the fnOS platform.
Recent reports have identified a significant security breach involving Feiniu (fnOS) Network Attached Storage (NAS) devices. These devices are being compromised by the Netdragon botnet, exploiting unpatched vulnerabilities within the fnOS platform.
The Netdragon botnet, first observed in October 2024, is targeting specific NAS systems by exploiting undisclosed security flaws. Attackers are utilizing these vulnerabilities to deploy a sophisticated malware system comprising a loader and a DDoS attack component.
Upon gaining access, the attackers install a modular malware system, enabling remote execution of arbitrary commands and integrating the devices into a botnet. This botnet is then used to conduct large-scale denial-of-service attacks. A critical aspect of the attack includes the deletion of the rsa_private_key.pem file, which poses a severe risk to data integrity and security.
Investigations have revealed that approximately 1,500 devices were compromised by the end of January. The affected devices are located primarily in China, the United States, and Singapore, impacting various sectors including software services and public administration.
Recent reports have identified a significant security breach involving Feiniu (fnOS) Network Attached Storage (NAS) devices.
Persistence and Defense Evasion Mechanisms
The Netdragon malware employs robust persistence and evasion tactics to maintain control over the infected devices. It establishes dual persistence through systemd services and kernel modules, ensuring survival through system reboots.
By tampering with the system’s hosts file, the malware blocks access to official update domains, preventing the application of security patches. It also employs dynamic key packing to obfuscate its code and deletes system logs to evade detection. Furthermore, it disrupts network monitoring tools to conceal its activities.
Recovery from this infection requires manual intervention. Users should remove any malicious firewall rules injected by the malware and delete the malicious kernel module async_memcpys.ko and user-mode service dockers.service . It is also vital to restore the system’s update path by correcting the hosts file and monitoring port 57199 to prevent reinfection.
Based on reporting by Cyber Security News.
