Sunday, March 26, 2023
AI Home Security
No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
No Result
View All Result
Morning News
No Result
View All Result
Home Cyber Security

Hiatus Campaign Infects DrayTek Routers for Cyber Espionage, Proxy Control

justmattg by justmattg
March 7, 2023
in Cyber Security
0
Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter



A cyber-espionage campaign featuring novel malware has been uncovered, targeting DrayTek routers at medium-sized businesses worldwide.

Unlike most spyware efforts, this campaign, dubbed “Hiatus” by Lumen Black Lotus Labs, has dual goals: to steal data in targeted attacks and to co-opt routers to become part of a covert command-and-control (C2) infrastructure for mounting hard-to-trace proxy campaigns.

The threat actors use known vulnerabilities to target DrayTek Vigor models 2960 and 3900 running an i368 architecture, according to an analysis this week on Hiatus from Black Lotus. Once the attackers achieve compromise, they can plant two unique, malicious binaries on the routers. 

The first is an espionage utility called tcpdump, which monitors router traffic on ports associated with email and file-transfer communications on the victim’s adjacent LAN. It has the ability to passively collect this cleartext email content as it transits the router.

“More established, medium-size businesses run their own mail servers, and sometimes have dedicated internet lines,” according to the report. “These networks utilize DrayTek routers as the gateway to their corporate network, which routes traffic from email servers on the LAN to the public internet.”

The second binary is a remote access Trojan (RAT) called HiatusRAT, which allows cyberattackers to remotely interact with the routers, download files, or run arbitrary commands. It also has a set of prebuilt functions, including two proxy functions that the threat actors can use to control other malware infection clusters via an infected Hiatus victim’s machine.

HiatusRAT’s Proxy Functions

The two proxy commands are “purpose-built to enable obfuscated communications from other machines (like those infected with another RAT) through the Hiatus victims,” according to the Black Lotus report.

They are:

  • socks5: Sets up a SOCKS version 5 proxy on the compromised router.
  • tcp_forward: For proxy control, this takes a specified listening port, forwarding IP, and forwarding port and transmits any TCP data that was sent to the listening port on the compromised host to the forwarding location. It establishes two threads to allow for bidirectional communications between the sender and the specified forwarding IP.

The ability to turn the router into a SOCKS5 proxy device “allows the threat actor to interact with malicious, passive backdoors such as Web shells via infected routers as a midpoint,” explains Danny Adamitis, principal threat researcher for Lumen Black Lotus. “Using a compromised router as the communications for backdoors and Web shells enables the threat actors to bypass geo-fencing-based defense measures and avoid being flagged on network-based detection tools.”

The TCP function, meanwhile, has likely been designed to forward beacons or interact with other RATs on other infected machines, which would “allow the router to be a C2 IP address for malware on a separate device,” according to the report.

All of this means that organizations shouldn’t underestimate their worth as a target, the report noted: “Anyone with a router who uses the internet can potentially be a target for Hiatus — they can be used as proxy for another campaign — even if the entity that owns the router does not view themselves as an intelligence target.”

Varied Types of Hiatus Victims

The campaign is unusually small, having infected only around 100 victims, mainly in Europe and Latin America.

“This is approximately 2% of the total number of DrayTek 2960 and 3900 routers that are currently exposed to the Internet,” according to Adamitis. “This suggests the threat actor is intentionally maintaining a minimal footprint to limit their exposure and maintain critical points of presence.”

In terms of espionage, some of the victims are “targets of enablement,” says the researcher, and include IT service and consulting firms.

“We believe the threat actors target these organizations to gain access to sensitive information about their customers’ environments,” using the scraped email communications to mount downstream attacks, Adamitis says.

He adds that a second grouping of victims can be considered targets of direct interest for data theft, “which included municipal government entities and some organizations involved in the energy sector.”

While the number of primary victims is small, the scope of the data theft suggests an advanced persistent threat as the culprit behind Hiatus.

“Based upon the amount of data that would be collected from these accesses, it leads us to believe that the actor is well resourced and is capable of processing large volumes of data, suggesting a state-backed actor,” Adamitis notes.

What to Learn From Hiatus

The key takeaway for businesses is that the conventional idea of perimeter security needs to be adapted to include routers.

“The benefits of using routers for data collection are that they are unmonitored, and all traffic passes through them,” Adamitis explains. “This stands in contrast to Windows machines and mail servers, which usually have endpoint detection and response (EDR) and firewall protections deployed in enterprise networks. This lack of monitoring allows the threat actor to collect the same information that would be achieved without directly interacting with any assets that might have EDR products pre-installed on them.”

To protect themselves, businesses need to make sure that routers are “routinely checked, monitored, and patched like any other perimeter device,” he says.

Organizations should take action: The Hiatus binaries were first seen last July, with new infections continuing up to at least mid-February. The attacks use version 1.5 of the malware, indicating that there could have been activity using version 1.0 prior to July. Black Lotus said that it fully expects the activity to continue.



Source link

READ ALSO

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month

Related Posts

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident
Cyber Security

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

March 26, 2023
Everything You Need to Know
Cyber Security

‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month

March 26, 2023
Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers
Cyber Security

Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers

March 26, 2023
U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals
Cyber Security

U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals

March 25, 2023
Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data
Cyber Security

Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data

March 25, 2023
Red Teaming at Scale to Uncover Your Big Unknowns
Cyber Security

Red Teaming at Scale to Uncover Your Big Unknowns

March 24, 2023
Next Post
Transparent Tribe Hackers Distribute CapraRAT via Trojanized Messaging Apps

Transparent Tribe Hackers Distribute CapraRAT via Trojanized Messaging Apps

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR NEWS

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

February 13, 2023
Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

February 11, 2023
The New Threats to Cryptocurrency Users

The New Threats to Cryptocurrency Users

February 12, 2023
Do you know who is watching you?

Do you know who is watching you?

January 2, 2023
PopID announces big customer deployment for face biometric payments in UAE

PopID announces big customer deployment for face biometric payments in UAE

February 14, 2023

EDITOR'S PICK

Opening This Year? A Look At Abu Dhabi’s Midfield Terminal

Opening This Year? A Look At Abu Dhabi’s Midfield Terminal

January 29, 2023
Accuhealth Wins 2022 BIG Innovation Award for Remote Patient Monitoring Technology

Accuhealth Wins 2022 BIG Innovation Award for Remote Patient Monitoring Technology

January 11, 2023
Chinese Hackers Utilize Golang Malware in DragonSpark Attacks to Evade Detection

Chinese Hackers Utilize Golang Malware in DragonSpark Attacks to Evade Detection

January 24, 2023
Android Spyware Targeting Financial Institutions

Android Spyware Targeting Financial Institutions

January 6, 2023

About

We bring you the best news & updates related to Home security, Cyber security and Biometric technology. Keep visiting our website for latest updates.

Follow us

Categories

  • Biometric Technology
  • Cyber Security
  • Home Security

Recent Posts

  • OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident
  • ‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month
  • Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers
  • U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals
  • Privacy Policy
  • Contact Us

© 2023 AI Home Security - All rights reserved.

No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology

© 2023 AI Home Security - All rights reserved.