HomeSecurityMalware ZuoRAT: Targets SOHO routers in North America and Europe

ZuoRAT Malware: Targets SOHO routers in North America and Europe

A recently discovered multi-stage remote access trojan (RAT) called ZuoRAT has been used to target remote workers via small office/home office (SOHO) routers across North America and Europe, undetected since 2020.

See also: Messenger: Malicious chatbots steal credentials for Facebook pages

ZuoRAT

In a report today, security researchers at Lumen's Black Lotus Labs who discovered the malware said the sophistication of this highly targeted campaign and the attackers' tactics, techniques, and procedures (TTPs) are the hallmarks of a state-sponsored threat actor.

The launch of this campaign coincides with the shift to remote work following the onset of the COVID-19 pandemic, which has drastically increased the number of SOHO routers (including ASUS, Cisco, DrayTek and NETGEAR) used by employees to access corporate assets from home.

See also: AMD investigates allegations of hacking and theft of company data

Once deployed on a router (without patches against known security flaws) with the help of an authentication, the ZuoRAT malware provided attackers with deep network reconnaissance and traffic collection through passive network sniffing.

ZuoRAT also allows lateral movement, so it can compromise other devices on the network and deploy additional malicious payloads (such as Cobalt Strike beacons) using DNS and HTTP hijacking.

Two more custom trojans were delivered to compromised devices during these attacks: a C++-based one named CBeacon that targets Windows workstations, and a Go-based one named GoBeacon that could likely infect Linux and Mac systems in addition to Windows devices .

ZuoRAT

Additional malware deployed on systems within the victims' networks (i.e., CBeacon, GoBeacon, and Cobalt Strike) provided threat actors with the ability to download and upload files, execute arbitrary commands, hijack network traffic, inject new processes, and gain persistence on compromised devices.

See also: Raccoon Stealer returns with a new version that steals your passwords

Based on the age of the samples submitted by VirusTotal and nine months of Black Lotus Labs telemetry, researchers estimate that the campaign has affected at least 80 targets so far.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS