Threat actors are using advanced malware to backdoor business-grade routers

Computer cable connected to router.

Researchers have discovered sophisticated malware that can turn business-grade routers into attacker-controlled listening posts to intercept emails and steal files.

In addition to passively capturing IMAP, SMTP, and POP emails, this malware backdoors your router with a remote access Trojan that allows attackers to download files and execute arbitrary commands. increase. Backdoors also allow attackers to flood data from other servers through your router, turning your device into a covert proxy to hide the true origin of malicious activity.

black lotus lab

“This type of agent shows that anyone with a router that uses the Internet can become a target. However, it could be used as a proxy for another campaign,” wrote a researcher at Black Lotus Labs at security firm Lumen. “Threat actors will likely continue to combine multiple compromised assets with each other to evade detection.”

The campaign, called Hiatus, has been going on since at least July last year, researchers say. So far we’ve mostly hit his end-of-life DrayTek Vigor models 2960 and 3900, which run the i386 architecture. These high-bandwidth routers support virtual private network connections for hundreds of remote workers. To date, approximately 100 routers have been infected, representing approximately 2% of the DrayTek 2960 and 3900 routers exposed to the Internet. Researchers suspect the unknown actors behind Hiatus intentionally keep their footprint small to maintain the stealthiness of their operations.

Black Lotus doesn’t yet know how the device is hacked in the first place. Either way, the malware is installed via a bash script deployed after exploitation. Download and install the two main binaries.

The first is HiatusRAT. Once installed, remote threat actors will be able to perform actions on the device, such as executing commands and new software,” and (2) using the included packet capture binary, to “email and monitor router traffic on ports related to file transfer communication.

The researchers believe that the attackers included SOCKS 5 software in function 1 to obfuscate the source of malicious traffic by proxying it through infected routers. thinking about. A Black Lotus researcher wrote:

HiatusRAT’s tcp_forward feature allows attackers to relay beacons through compromised devices from another infection to reach upstream C2 nodes. Conversely, an attacker could echo commands from upstream infrastructure through a compromised router in the target device’s country to her webshell, interacting with a more passive agent to enable geofencing-based security measures. You can also obscure the true source by passing the .

black lotus lab

The tcpdump binary that enables packet capture was the engine behind feature 2. This allowed Hiatus to monitor traffic on ports sending email and FTP communications from adjacent LANs. Pre-configured to work with IMAP, POP, and SMTP email protocols.

black lotus lab

Hiatus primarily targets DrayTek routers running the i386 architecture. However, researchers have found prebuilt binaries compiled for ARM, MIPS64 big endian, and MIPS32 little endian platforms.

HiatusRAT’s packet capture capabilities should serve as a significant wake-up call to anyone who continues to send unencrypted email. In recent years, email services have improved to automatically configure accounts to use protocols such as SSL/TLS on port 993 and STARTTLS on port 143.

Also, remember that your router is an Internet-connected computer, so regular attention should be paid to ensure compliance with updates and other measures such as changing all default passwords. is also recommended. For businesses, it may also make sense to have a dedicated router monitor.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *