The Goldoon botnet has been spotted attacking D-Link routers, exploiting a critical technical security flaw that has existed for almost a decade.

Its purpose is to use compromised devices as tools to carry out more attacks.
The identified vulnerability, codenamed CVE-2015-2051 with a CVSS score of 9.8, affects D-Link DIR-645 routers, allowing hackers to execute commands remotely via specially crafted HTTP requests.
Read more: US: Charges against Moldova for operating botnet
When hackers breach the security of a targeted device, they gain full, controlled access. This allows them to extract information from the system, communicate with a control (C2) server, and then use the devices to conduct further attacks, such as distributed denial-of-service (DDoS) attacks, said Fortinet FortiGuard Labs researchers Cara Lin and Vincent Li.
Telemetry data from the security shows a significant increase in botnet activity since April 9, 2024.
It all starts with the exploitation of CVE-2015-2051 to retrieve a dropper script from a remote router, which is responsible for receiving the next-stage payload for different Linux, including aarch64, arm, i686, m68k, mips64, mipsel, powerpc, s390x, sparc64, x86-64, sh4, riscv64, DEC Alpha, and PA-RISC.
The payload is then launched onto the compromised device and acts as a server to download the Goldoon malware from a remote server. The downloader then removes the executable file and self-deletes, seeking to obliterate any trace of its presence.
Any attempt to access the endpoint from a web browser results in an error message: “Sorry, if you are an FBI agent, we cannot offer you assistance 🙁 Please leave, otherwise there will be consequences :)”
Goldoon improves persistence on the host computer through a variety of automated execution methods and connects to a command and control (C2) server, awaiting a command for monitoring actions.
It includes “27 impressive different techniques” for dealing with DDoS attacks, implementing a variety of protocols such as DNS, HTTP, ICMP, TCP, and UDP.
The researchers stated that “Although CVE-2015-2051 is not a recent vulnerability and exhibits low attack complexity, its security implications are critical as it can lead to remote code execution.”
Botnets continue to evolve as they seek to exploit more and more devices, increasing their effectiveness. Hackers and organizations developing advanced persistent threats (APTs) have shown a keen interest in using compromised routers as a means of achieving anonymity.
“Hackers are renting compromised routers to other hackers, while also providing them to companies involved in commercial intermediation,” Trend Micro said in its recent cybersecurity report.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
"Threat actors such as the Sandworm gang used their own proprietary proxy botnets, while the Pawn Storm APT group had access to a criminal Ubiquiti EdgeRouters proxy botnet."
By using compromised routers as proxy servers, the goal is to hide traces of their presence and make it difficult to detect malicious activities by merging their activity.
The US government took action in February to dismantle parts of a botnet called MooBot, which, among other internet-facing devices such as Raspberry Pi and VPS servers, primarily leveraged Ubiquiti EdgeRouters.
Trend Micro announced that routers are targets for Secure Shell (SSH) attacks, spam messages with pharmaceutical content, exploitation of SMB reflectors in NTLMv2 relay attacks, handling stolen certificates on phishing, supporting multiple proxy scenarios, cryptocurrency , and sending fake phishing emails.
Ubiquiti routers were attacked by a different attacker, who infected them with malware known as Ngioweb. This software turned the devices into exit nodes for a commercially available home proxy botnet.

See also: Cuttlefish Malware: Hacks routers for the purpose of secret surveillance
All of these findings raise concerns about the implementation of different types of malware, which are used to hijack routers on networks under the control of hackers. This turns them into invisible monitoring stations, capable of monitoring all network traffic.
“Internet routers are a prime target for hackers, as they often suffer from inadequate security oversight, lax password policies ,infrequent updates, and can run advanced operating systems that allow the installation of malware. Such software includes cryptocurrency miners, proxies, malware , malicious scripts, and web servers,” Trend Micro reports.
Source: thehackernews
