Appears new malware HiatusRAT targeting enterprise routers
New "Hiatus" malware campaign attacks enterprise routers
A new malware campaign, dubbed "Hiatus" is targeting small business routers through the use of HiatiusRAT malware.
On March 6, 2023, research firm Lumen published a blog post discussing this malicious campaign. Lumen's blog post states that "Lumen Black Lotus Labs has identified another never-before-seen campaign involving compromised routers".
HiatusRAT is a type of malware known as a Remote Access Trojan (RAT). The Remote Access Trojan is used by cybercriminals to gain remote access and control over the target device. The latest version of the HiatusRAT malware appears to have been in use since July 2022.
Lumen's blog post also states that "HiatusRAT allows the threat actor to remotely interact with the system, and it uses prebuilt functionality - some of which are highly unusual - to transform the compromised machine into as a secret proxy for the threat agent".
Using the command line utility "tcpdump", HiatusRAT can intercept network traffic passing through the targeted router, allowing data theft. Lumen also speculates that the bad guys involved in this attack aim to establish a secret proxy network through the attack.
HiatusRAT is targeting specific types of routers
HiatusRAT malware is being used to attack old DrayTek Vigor VPN routers, specifically models 2690 and 3900 running i386 architecture. These are high-bandwidth routers used by businesses to support VPNs for remote workers.
These router models are often used by small and medium business owners who are at risk of becoming a specific target in this campaign. Researchers do not currently know how these DrayTek Vigor routers were compromised at the time of writing.
More than 4,000 devices were found to be vulnerable to this malware campaign in mid-February, meaning many businesses are at risk.
Attackers only targeted a few DrayTek routers
Of all the DrayTek 2690 and 3900 routers connected to the Internet today, Lumen reported an infection rate of just 2%.
This shows that attackers are trying to leave a minimal footprint in order to limit exposure and avoid detection. Lumen also suggests in the aforementioned blog post that this tactic is also being used by attackers to "maintain critical points of presence".
HiatusRAT creates big risks for businesses
At the time of this writing, HiatusRAT poses a risk to many small businesses, with thousands of routers still exposed to this malware. Time will tell how many DrayTek routers are successfully targeted in this malicious campaign.
You should read it
- Mandrake: Super sophisticated Android malicious code, only 4 years to be discovered
- How to Avoid or Remove Mac Defender Malware from Mac OS X V10.6 or Earlier
- How to detect and remove malware Agent Smith on Android
- Reload for cheap routers Enterprise features
- How to detect VPNFilter malware before it destroys the router
- How many types of malware do you know and how to prevent them?
- 10 typical malware types
- What is Safe Malware? Why is it so dangerous?
May be interested
- How to protect your phone from SparkKitty photo-stealing malwareunfortunately, malware is getting smarter and is now targeting sensitive information stored as photos, like the latest sparkkitty malware on phones.
- Detecting dangerous backdoors targeting both Windows, macOS and Linuxinternational cybersecurity researchers have just issued an urgent notice about a new type of cross-platform malware called 'sysjoker' that has been appearing all over the world.
- Detects new Xcode malware targeting iOS developersinternational cybersecurity experts have broadcast an urgent message about a malicious xcode project called xcodespy. the malware is currently targeting ios software developers in a supply-chain attack.
- Warning: The Joker malware has infected over 500,000 Huawei Android devicesthe joker, one of the most persistent and dangerous strains of malware targeting android devices, has just been discovered.
- How to detect VPNFilter malware before it destroys the routervpnfilter is a destructive malware for routers, iot devices and even some network storage devices (nas). how do you detect if your devices are infected with vpnfilter malware? and how can you remove it?
- Learn about Vue routersif you want to create a fully functional front-end application, then vue-router and vue-resource are two great key elements in vuejs. today's article will delve into the vue router.
- 3 ways hackers can attack home routersa router is an important source of data transmission in the home. computers, laptops, tablets and phones all use routers to transfer data to websites worldwide.
- New Cuckoo Malware Is Targeting Mac Users: Here's How to Spot It!although mac users are less likely to encounter viruses than windows users, hackers still find ways to introduce viruses to wreak havoc on macos. one of them is the cuckoo virus.
- How to protect PowerShell from fileless attacks from the Remcos RAT malwareexcel users need to be on guard as a newly discovered phishing campaign is targeting microsoft's spreadsheet application.
- Network basics: Part 2: Understanding the Routerrouters are an important networking device that almost every home owns but they really don't know much about them. in fact, most people don't even know what the router looks like, it's different from the modem.