Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Dark_Code_x

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 28, 2020
Messages
6,776
Reaction score
726
Points
212
Awards
2
  • Somebody Likes you
  • First post
The attacks began in late November or early December last year and may still be ongoing.






Netlab researchers at Qihoo 360, a Chinese security company, reported two recently discovered malicious campaigns in which cybercriminals exploited zero-day vulnerabilities in Taiwanese-based DrayTek network devices.

According to experts, at least two separate cybercriminal groups used two critical remote command injection vulnerabilities ( CVE-2020-8515 ), affecting corporate switches, load balancers, routers and VPN gateways of DrayTek Vigor to intercept network traffic and install backdoors.

According to experts, the attacks began in late November or early December last year and may still continue against thousands of vulnerable Vigor 2960, 3900, 300B devices that have not yet received the latest firmware.

NetLab researchers did not associate the attacks with any particular grouping, but confirmed that the first group simply spied on network traffic, and the second used the command injection vulnerability in rtick to create backdoors and a system account with the username “wuwuhanhan” and the password “caonimuqin”.

According to experts, installing a fixed version of the firmware will not delete backdoor accounts automatically if the system has already been compromised.

Problems affect Vigor2960 versions below 1.5.1, Vigor300B below 1.5.1, Vigor3900 below 1.5.1, VigorSwitch20P2121 2.3.2 and below, VigorSwitch20G1280 2.3.2 and below, VigorSwitch20P1280 v2.3.2 and below, VigorSwitch20G2280 v2.3.2 and below VigorSwitch20G2280 v2.3.2 and below v2.3.2 and below. The manufacturer fixed the vulnerability in firmware version 1.5.1.
 
Ad End 1 February 2024
Top