Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Feiniu NAS Devices Infected in Large-Scale Netdragon Botnet Attack Exploiting Unpatched Vulnerabilities

Recent reports have identified a significant security breach involving Feiniu (fnOS) Network Attached Storage (NAS) devices. These devices are being compromised by the Netdragon botnet, exploiting unpatched vulnerabilities within the fnOS platform.

Recent reports have identified a significant security breach involving Feiniu (fnOS) Network Attached Storage (NAS) devices. These devices are being compromised by the Netdragon botnet, exploiting unpatched vulnerabilities within the fnOS platform.

The Netdragon botnet, first observed in October 2024, is targeting specific NAS systems by exploiting undisclosed security flaws. Attackers are utilizing these vulnerabilities to deploy a sophisticated malware system comprising a loader and a DDoS attack component.

Upon gaining access, the attackers install a modular malware system, enabling remote execution of arbitrary commands and integrating the devices into a botnet. This botnet is then used to conduct large-scale denial-of-service attacks. A critical aspect of the attack includes the deletion of the rsa_private_key.pem file, which poses a severe risk to data integrity and security.

Investigations have revealed that approximately 1,500 devices were compromised by the end of January. The affected devices are located primarily in China, the United States, and Singapore, impacting various sectors including software services and public administration.

Recent reports have identified a significant security breach involving Feiniu (fnOS) Network Attached Storage (NAS) devices.
Joseph Cain · Thehackingpost

Persistence and Defense Evasion Mechanisms

The Netdragon malware employs robust persistence and evasion tactics to maintain control over the infected devices. It establishes dual persistence through systemd services and kernel modules, ensuring survival through system reboots.

By tampering with the system’s hosts file, the malware blocks access to official update domains, preventing the application of security patches. It also employs dynamic key packing to obfuscate its code and deletes system logs to evade detection. Furthermore, it disrupts network monitoring tools to conceal its activities.

Advertisement

Recovery from this infection requires manual intervention. Users should remove any malicious firewall rules injected by the malware and delete the malicious kernel module async_memcpys.ko and user-mode service dockers.service . It is also vital to restore the system’s update path by correcting the hosts file and monitoring port 57199 to prevent reinfection.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories