Monday, April 28, 2025
HomeBotnetD-Link Warns of Botnets Exploiting End-of-Life Routers

D-Link Warns of Botnets Exploiting End-of-Life Routers

Published on

SIEM as a Service

Follow Us on Google News

D-Link warned users of several legacy router models about known vulnerabilities actively exploited by botnets.

These devices, which have reached End-of-Life (EOL) and End-of-Service (EOS), are at heightened risk of being targeted by malware strains known as “Ficora” and “Capsaicin.”

Vulnerable Legacy Routers

The affected devices include the following models:

- Advertisement - Google News
  • DIR-645 (US/Global)
  • DIR-806 (Non-US)
  • GO-RT-AC750 (Non-US)
  • DIR-845L (Non-US)

These routers, spanning all hardware revisions and firmware versions, are no longer supported.

Their firmware development ceased well before 2024. For instance, DIR-645 reached EOS in 2018, while other international models like DIR-806, GO-RT-AC750, and DIR-845L were discontinued between 2016 and 2018.

Critical Vulnerabilities Exploited

Reports from Fortiguard detail how the malware botnets Ficora and Capsaicin exploit these unsupported routers to carry out malicious activities.

These botnets target outdated firmware, taking advantage of security gaps that no longer receive updates or patches.

Once compromised, these routers can be used for Distributed Denial-of-Service (DDoS) attacks, data theft, or launching further malware campaigns.

D-Link has emphasized that continuing to use EOL/EOS devices presents significant cybersecurity risks. Unsupported devices often lack critical firmware updates and security patches, making them highly susceptible to modern cyberattacks.

D-Link strongly advises users to retire these routers immediately and replace them with newer models that receive regular firmware updates.

For consumers in North America, D-Link suggests the following actions:

  1. Retire and Replace: Replace the affected models with current products that receive firmware updates.
  2. Update Firmware: If immediate replacement isn’t possible, ensure the device runs the latest firmware.
  3. Enhance Security: Change passwords for web configuration access and enable Wi-Fi encryption with strong, unique passwords.
  4. Stay Vigilant: Regularly monitor for firmware updates, though no further updates will be released for EOL routers.

While this advisory primarily targets users in North America, D-Link urges all international users of legacy devices to consult their regional D-Link offices for tailored recommendations.

The company highlights the importance of staying ahead of technological advancements and ensuring equipment aligns with current cybersecurity standards.

D-Link’s decision to classify these models as EOL/EOS aligns with the natural lifecycle of technological products.

As these devices age, they become obsolete due to security measures and advancements in wireless technology. The company stresses the importance of upgrading to newer models to safeguard users against evolving threats.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...