Sophisticated malware is targeting business routers, enabling unauthorized
news.dailyheadliner.com
Thursday, June 8, 2023
No Result
View All Result
  • Login
  • Home
  • Business Blues
  • Crypto Snooze
  • funances
  • Health Crap
  • Politricks
  • Stuff to Buy
  • More Sports
  • Stocks
  • Tech Again
  • Travel Woes
  • Home
  • Business Blues
  • Crypto Snooze
  • funances
  • Health Crap
  • Politricks
  • Stuff to Buy
  • More Sports
  • Stocks
  • Tech Again
  • Travel Woes
No Result
View All Result
news.dailyheadliner.com
No Result
View All Result
Home Tech

Sophisticated malware is targeting business routers, enabling unauthorized access.

March 6, 2023
in Tech
0 0
Sophisticated malware is targeting business routers, enabling unauthorized access.



Advanced malware has been discovered by researchers that targets business-grade routers, turning them into attacker-controlled listening posts that can steal files and capture email traffic. The campaign, which has been named Hiatus, has been operative since at least last July, hitting primarily end-of-life DrayTek Vigor models 2960 and 3900 that help VPN connections for over hundreds of remote workers. As of now, the threat actor behind the campaign has infected approximately 2% of the DrayTek 2960 and 3900 routers exposed on the internet, equating to approximately 100 routers. Experts believe that the attacker has chosen to keep their footprint small to maintain the stealth of their operation.
The malware passes emails in IMAP, SMTP, and POP protocols, where the malware also backdoors routers with a remote access Trojan. The remote access Trojan allows the attackers to download files and execute commands of their choice. It also enables attackers to forward data from other servers through the router, thereby converting it into a private proxy that conceals the origin of malicious activities.   
Lumen’s Black Lotus Labs researchers wrote: “This type of agent demonstrates that anyone with a router who uses the internet can potentially be a target – and they can be used as a proxy for another campaign – even if the entity that owns the router does not view themselves as an intelligence target,”. Moreover, researchers found that Hiatus comes with two main binaries, with the first being HiatusRAT. Once installed, it allows a remote threat actor to run commands or new software on the device. The RAT also comes with two unusual additional functions built in: (1) “convert the compromised machine into a covert proxy for the threat actor,” and (2) use an included packet-capture binary to “monitor router traffic on ports associated with email and file-transfer communications.”
The second binary is a tcpdump, which enables packet capture. This binary was the engine behind function 2, which provided Hiatus with the ability to monitor traffic on ports transmitting email and FTP communications from the adjacent LAN. Hiatus also targets a variety of architectures including prebuilt binaries compiled for ARM, MIPS64 big-endian, and MIPS32 little-endian platforms. 
Black Lotus is still uncertain about the sequence of events of how the devices were initially hacked. However, once the attack has commenced, the malware is deployed through a bash script that installs the two main binaries. 
The packet-capture ability of the HiatusRAT serves as a major warning for anyone who still sends emails without encryption. Therefore emails services will configure accounts automatically to use protocols such as SSL/TLS over port 993 or STARTTLS on port 143. Anyone who still sends email in plaintext will likely regret it. 
Additionally, routers are internet-connected computers, so it’s important to regularly attend to them for updates and changing all default passwords. It makes sense for businesses to use dedicated router monitoring.

ADVERTISEMENT

Share this:

  • Twitter
  • Facebook
  • LinkedIn
  • Reddit
  • Tumblr
  • Pinterest
  • Pocket
  • Telegram
  • WhatsApp
  • Skype

Related

Related Posts

“Breaking news: VIVA Cruises to unleash yet another floating prison, the VIVA ENJOY, on unsuspecting travelers in 2024.”
Travel

“Breaking news: VIVA Cruises to unleash yet another floating prison, the VIVA ENJOY, on unsuspecting travelers in 2024.”

0
How to Protect Yourself From Wildfire Smoke if You’re at High Risk of Health Effects
Health

How to Protect Yourself From Wildfire Smoke if You’re at High Risk of Health Effects

0
PFL 4 Results: Loughnane vs. Pinedo
Sports

Another Boring Night of PFL 4 Fights: Surprise, Surprise!

0
Ethereum
Crypto News

Ethereum (ETH) Expected to Hit $11,800: Timing Revealed by VanEck

0
“Burgers and Belligerence: TV Star Arrested for Beefing with Capitol Cops on Jan. 6th – Looks Like Someone Got Their Patty in a Flap!”
Finance

“Burgers and Belligerence: TV Star Arrested for Beefing with Capitol Cops on Jan. 6th – Looks Like Someone Got Their Patty in a Flap!”

0
John Thornhill's Digital Mentorship Monthly.
Sports

John Thornhill’s Digital Mentorship Monthly.

0
Load More

Top Posts & Pages

  • Bitcoin's Drop Below $26K Causes Over $300M in Liquidations.
    Bitcoin's Drop Below $26K Causes Over $300M in Liquidations.
  • Rare “Gorilla Cherry” Secret Helps Support A Healthy Prostate
    Rare “Gorilla Cherry” Secret Helps Support A Healthy Prostate
  • How to Protect Yourself From Wildfire Smoke if You’re at High Risk of Health Effects
    How to Protect Yourself From Wildfire Smoke if You’re at High Risk of Health Effects
  • Another Boring Night of PFL 4 Fights: Surprise, Surprise!
    Another Boring Night of PFL 4 Fights: Surprise, Surprise!
  • Ethereum (ETH) Expected to Hit $11,800: Timing Revealed by VanEck
    Ethereum (ETH) Expected to Hit $11,800: Timing Revealed by VanEck
  • "Burgers and Belligerence: TV Star Arrested for Beefing with Capitol Cops on Jan. 6th - Looks Like Someone Got Their Patty in a Flap!"
    "Burgers and Belligerence: TV Star Arrested for Beefing with Capitol Cops on Jan. 6th - Looks Like Someone Got Their Patty in a Flap!"
  • New Supplement May Change The Way You Diet

    New Supplement May Change The Way You Diet

    0 shares
    Share 0 Tweet 0
  • The Top 3 Fat Burning Teas, Which is right for you?

    0 shares
    Share 0 Tweet 0
  • Most startups have been overestimated sooner than 2021, and now it’s inflicting issues

    0 shares
    Share 0 Tweet 0
  • Is There a Real Cure For Diabetes

    0 shares
    Share 0 Tweet 0
  • Trump Executive Privilege Claim Shattered As Judge Orders Mark Meadows And Others To Testify

    0 shares
    Share 0 Tweet 0

Tags

adaderana (303) ada derana (303) adaderana.lk (303) Athlete (1348) Bitcoin (832) biz (486) Breaking News: Technology (355) breaking news in sri lanka (303) Business (785) business news (1327) Computer (262) Crypto (792) Cryptocurrency (271) Electronics (265) Extreme (1359) Football (1460) Golf (1371) Hockey (1361) Internet (354) lankan news (303) latest sri lankan news (303) Marathon (1359) Market (326) Markets (315) News (1220) Runner (1347) Running (1382) Shopping (347) Soccer (1526) Social media (293) Softball (1350) Software (487) Sports (1418) sri lanka business news (303) sri lanka gossip (303) sri lanka hot news (303) sri lanka news (303) sri lanka sports news (303) stocks (323) talking (492) TechCrunch (1622) Technology (1301) Tennis (1408) Training (1360) Travel (315)

Subscribe to Blog via Email

Enter your email address to subscribe and receive notifications of new posts by email.

ADVERTISEMENT
  • Home
  • Business Blues
  • Crypto Snooze
  • funances
  • Health Crap
  • Politricks
  • Stuff to Buy
  • More Sports
  • Stocks
  • Tech Again
  • Travel Woes
No Result
View All Result
  • Home
  • Business Blues
  • Crypto Snooze
  • funances
  • Health Crap
  • Politricks
  • Stuff to Buy
  • More Sports
  • Stocks
  • Tech Again
  • Travel Woes

© news - All Rights Are Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.