Feiniu (fnOS) Network Attached Storage (NAS) devices face a large-scale compromise by the Netdragon malware family, first identified in October 2024.
Attackers exploit undisclosed vulnerabilities in exposed services to implant this botnet, enabling DDoS attacks and remote control across roughly 1,500 infected devices by late January 2026.
Qi An Xin XLab’s analysis reveals targeted adaptations in fnOS, with evasion tactics that block updates and complicate removal.
Infection Scale and Impact
Netdragon opens an HTTP backdoor on port 57132 (later shifted to 57199) for remote command execution via GET /api requests with hex-encoded parameters.
XLab’s global asset mapping identified over 1,000 suspicious IPs tied exclusively to Feiniu devices, confirmed by passive DNS links to domains such as xd. killaurasleep.top used for payload downloads.
C2 panels showed 1,143 online bots by January end, with infections spanning China, the US, Singapore, and Australia across industries like IT services and manufacturing.
The botnet launches undirected DDoS via Telegram bots and HTTP APIs, hitting broad targets without clear patterns.

On February 1, 2026, operators issued a command to delete rsa_private_key.pem from the Feiniu NAS, raising data encryption risks, though the intent remains unclear. This persistent threat amplifies dangers for exposed storage systems.
Malware Components and Evasion
Netdragon uses a modular design with Loader and DDoS components tailored to fnOS. The Loader clears traces by wiping logs in paths such as/var/log/accountsrv/, /var/log/*.log, /usr/trim/logs/, and audit files, thereby hiding intrusions.
It blocks updates by hijacking hosts’ entries for apiv2-liveupdate.fnnas.com and update-service.test.teiron-inc.cn to 0.0.0.0, kills recovery services like sysrestore_service, and deletes files such as /tmp/trim-update.

Persistence layers include appending wget commands to system_startup.sh for next-stage drops, systemd services like %s.service (e.g., dockers.service), and rc. local entries, and kernel module async_memcpys.ko.
The DDoS module decrypts strings via ChaCha20 with hardcoded KEY_HEX (161E194B…) and NONCE_HEX, outputs “PWNED FROM NETDRAG”, renames to sshd, hides /proc/[PID] under /tmp, and self-deletes after copying to /sbin/gots.
C2 communication uses IPs like 45.95.. or aura.kabot.icu on ports 3489/5098/6608/7489, with a custom protocol: uint8 msgType, uint16 pLen/padding/randLen, followed by randByte and payload.

Stages include handshake (msgType 4), botid (5), DDoS (1), and exec cmd (8), secured by session key XOR and dual Nonces. During a DDoS attack, it renames /usr/bin/cat to cat2 and kills network_service/resmon_service to mask traffic.
Post-exposure, Netdragon deletes nft/iptables rules blocking C2 (e.g., nft list ruleset -a | grep C2IP …), packs binaries with 8-byte dynamic keys, and swaps C2 infrastructure.
This raises remediation costs; users report failed upgrades, as seen on fnNAS forums. Recovery demands manual fixes: purge firewall rules, delete async_memcpys.ko, and dockers. service, restore hosts, and scan port 57199.
According to XLab, feiniu owners must isolate devices, apply patches if possible, and monitor for backdoors. This campaign underscores NAS risks in botnet evolution and urges vigilance in firmware management.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.