Another new router malware is sniffing around for your login details

another new router malware is sniffing around for your login details

Bästa tjänsterna för lösenordshantering

Cybersecurity researchers from Black Lotus Labs recently observed a new infection campaign, targeting both enterprise-level and small office/home routers (SOHO) with information-stealing malware.

According to the researchers, the unidentified threat actors are either abusing a zero-day vulnerability, or simply brute-forcing their way into routers, after which they plant a brand new malware variant.

This malware, called Cuttlefish, creates a proxy, or a VPN tunnel, through which it siphons sensitive data passing through the device, such as login credentials.

Connections to HiatusRAT

The malware also comes with different obfuscation techniques, successfully bypassing solutions designed to spot unusual sign-in attempts. It also works well around network segmentation, or endpoint monitoring.

There are many unknowns surrounding the campaign, Black Lotus Labs further explains, including the identity of the attackers, the number of infected endpoints, or the motive for the attack. So far, the majority of compromised devices are located in Turkey, with a few others apparently impacting satellite phone and data center services.

While the identity of the attackers is unknown, the researchers spotted a few similarities with a threat actor they track as HiatusRAT. They stressed that it’s impossible to conclusively connect the two at this time. HiatusRAT was seen in the past advancing Chinese state interests, although actual affiliation has not been confirmed.

Whoever the adversary is, and whatever their motives are, to protect your routers Black Lotus Labs says you should make sure your login credentials are not weak, and should update them regularly. Routers should be frequently restarted, their firmware updated, and remote access to the management interface blocked.

Furthermore, you should keep an eye on unusual logins from residential IP addresses, secure traffic with TLS/SSL, and inspect devices for rogue IPtables. You should implement certificate pinning when connecting to assets of high value, and just replace the device when it reaches end of life.

More from TechRadar Pro

    OTHER NEWS

    14 minutes ago

    'Sachin Tendulkar would leave his ego at home': Virat Kohli dropped, 'God' triumphs over 'King' in 'Ultimate Playing XI'

    14 minutes ago

    Why Brooks Koepka Isn't Wearing LIV Golf Logos At The PGA Championship

    14 minutes ago

    Oilers’ big guns, power play uncharacteristically quiet in Game 5 loss

    14 minutes ago

    Dairy farmers concerns at Fonterra's 'step change'

    14 minutes ago

    Gabba won't lose seats in 2032 Olympic rebuild

    14 minutes ago

    ASX falls at Friday’s close despite reaching 20-day high on Thursday

    16 minutes ago

    European markets lower after snapping nine-day winning streak; Richemont up 6.3%

    19 minutes ago

    I'm A Celebrity co-host Julia Morris cuts a chic figure in cream and pink ensemble as she arrives at Sydney Airport

    19 minutes ago

    Video: Urgent warning as 2,000 people fall ill with nasty virus in just a WEEK

    19 minutes ago

    Video: Rowville, Melbourne abduction: Mother opens up about terrifying moment she and her baby were abducted

    19 minutes ago

    Video: Terrifying moment a rogue propeller strap smashes through a plane's fuselage and hits a passenger in mid air

    19 minutes ago

    Step into comfort and style: Calla Shoes' bunion-friendly sandals are redefining summer footwear: 'Look stylish and so comfortable'

    19 minutes ago

    Pictured: 'Gorgeous' one-year-old girl who died after being hit by land Rover in church car park as family say they are 'absolutely devastated'

    19 minutes ago

    Video: Meghan Markle and Prince Harry's Nigeria trip left the King and the Prince of Wales 'absolutely furious', royal author claims

    19 minutes ago

    Making a LOT of dough! How two brothers who quit their jobs to sell food from the back of a van have turned Pizza Pilgrims into a £30m empire - and count two Prime Ministers among their fans

    19 minutes ago

    Daughter of Stuart Lubbock who drowned in Michael Barrymore's pool says entertainer has 'no shame' as he brags of new life in Barcelona 23 years after tragedy

    19 minutes ago

    Turkey neck? This cult £32 tightening neck cream that sells every 60 SECONDS is now infused with 24K gold to leave you with a gorgeous glow

    19 minutes ago

    Revealed: Hero police officer sacked for sending vile texts about Harvey Price and Jimmy Savile had public Twitter account ridiculing Muslim women and gay people before he joined the force

    19 minutes ago

    Step into comfort and style: Calla Shoes' bunion-friendly sandals are redefining summer footwear: 'Look stylish and so comfortable'

    19 minutes ago

    Manchester United XI vs Brighton: Predicted lineup, confirmed team news and injury latest for Premier League

    19 minutes ago

    Every UK town at risk of flooding this weekend as Brits warned of travel chaos - full list

    20 minutes ago

    Starving Gaza children dying the 'size of a skeleton'

    20 minutes ago

    "Monumental", "insane" and "never expected this": escapees (and Pogacar) marvel at Alaphilippe's masterpiece

    20 minutes ago

    UFC Analyst Predicts Conor McGregor vs Michael Chandler Fight Result

    20 minutes ago

    Hamas releases video said to show attack on Israeli tank in Jabalia, Gaza

    20 minutes ago

    Golf-Sizzling Schauffele grabs first round lead at PGA Championship

    20 minutes ago

    Gudrun Ure obituary

    20 minutes ago

    New York Mets Owner Deletes Tweet, Then Clarifies His Thought About Selling

    20 minutes ago

    Abdul Ebrahim: Mistakes happen, but nothing wrong with SA referees

    20 minutes ago

    Shares of Cartier owner Richemont climb 6% on record full-year sales, new CEO

    21 minutes ago

    Insurer warns owners of ‘Saltburn effect’ from using stately homes for filming

    21 minutes ago

    Liverpool expected to sign a replacement for Salah

    21 minutes ago

    PGA Championship: Sizzling Schauffele sets the pace with record-equalling opening round

    21 minutes ago

    Watch live: Jeremy Hunt promises tax cuts if Tories win general election

    21 minutes ago

    Fifa seek legal advice over Palestine proposal to suspend Israel

    21 minutes ago

    The key data as Jurgen Klopp leaves Liverpool with impressive statistical record

    21 minutes ago

    Scrap VAR for all subjective decisions – Harry Maguire

    21 minutes ago

    He is an icon – Virgil van Dijk leads tributes to departing boss Jurgen Klopp

    22 minutes ago

    The Latest | U.S.-built pier begins carrying aid to Gaza

    22 minutes ago

    Postnatal retreat offers new moms 24/7 help — but it doesn’t come cheap