Hackers have infected the firmware of TP-Link routers in order to attack entities in the European Union.

A state-backed Chinese hacking group, dubbed “Camaro Dragon,” has infected TP-Link home routers with a custom “Horse Shell” malware used to attack foreign affairs organizations in Europe.
The backdoor malware is deployed in a malicious and customized firmware, designed specifically for TP-Link routers, so that hackers can launch attacks that appear to originate from home networks.
See also: US Department of Justice focuses on hunting DeFi hackers
The malware being deployed allows threat actors full access to the device, including executing shell commands, uploading and downloading files, and using it as a SOCKS proxy to relay communication between devices.
The Horse Shell TP-Link firmware implant was discovered by Check Point Research in January 2021, which reports that the hackers' activity coincides with that of the Chinese hacking group "Mustang Panda" detailed in reports by Avast and ESET.
Check Point is tracking this activity separately, using the name “Camaro Dragon” for the cluster of activities, despite the similarities and significant overlap with Mustang Panda.
The attribution was based on the attackers' server IP addresses, requests with hard-coded HTTP headers found on various Chinese websites, numerous typos in the binary code indicating that the author is not a native English speaker, and the trojan's functional similarities to the APT31 router implant "Pakdoor."
See also: Apple App Store: Blocked over 1.7 million dangerous apps in 2022
TP-Link firmware implant
While Check Point has not specified how attackers infect TP-Link routers with the malicious firmware image, it said it could be done by exploiting a vulnerability or by compromising administrator credentials .
Once a threat actor gains administrator access to the management interface, they can remotely update the device with the custom firmware image.
Through its research, Check Point found two samples of trojanized firmware images for TP-Link routers, which contained extensive file modifications and additions.
Check Point compared the malicious TP-Link firmware to a legitimate version and found that the kernel and uBoot sections were identical. However, the malicious firmware used a custom SquashFS file system, which contained additional malicious file elements that are part of the Horse Shell backdoor implant.
The firmware also modifies the online management panel, preventing the device owner from flashing a new firmware image to the router and ensuring the infection persists.

The Horse Shell backdoor
When the Horse Shell backdoor implant is initialized, it will instruct the operating system not to terminate its process when SIGPIPE, SIGINT, or SIGABRT commands are issued and to turn into a daemon to run in the background.
The backdoor will then connect to the command and control (C2) server to send the victim's machine profile, including username, operating system version, time, device information, IP address, MAC address, and supported implantation features.
Horse Shell will now run silently in the background waiting for one of the following three commands:
- Launch a remote shell, giving threat actors full access to the compromised device.
- Perform file transfer activities, including sending and receiving, basic file editing, and directory enumeration.
- Initiate tunneling to hide the origin and destination of network traffic and hide the address of the C2 server.

The researchers say that the Horse Shell firmware implant is firmware-agnostic, so in theory it could work with firmware images from other routers from different vendors.
It’s no surprise that state-sponsored hackers target poorly secured routers, which are often the target of botnets for DDoS attacks or crypto-mining. This is because routers are often overlooked when implementing security measures and can act as a covert base for attacks, obscuring the attacker’s origin.
See also: UNC3944: Uses Azure Serial Console to secretly access VMs
Users are advised to apply the latest firmware update for their router model to patch any existing vulnerabilities and change the default administrator password to something strong. However, even more crucially, disable remote access to the device's admin panel and make it accessible only from the local network.
Information source: bleepingcomputer.com
