HomeSecurityHiatusRAT targets webcams and DVRs

HiatusRAT targets webcams and DVRs

The FBI has warned that new HiatusRAT malware attacks are scanning and infecting vulnerable webcams and DVRs exposed to the internet .

See also: RAT Attacks: What They Are and How You Can Protect Yourself

HiatusRAT

As a PIN alert published on Monday explains, attackers are focusing their attacks on devices that are still awaiting security updates or have already reached the end of their support.

Threat actors are primarily targeting Hikvision and Xiongmai devices with telnet access using Ingram , an open-source webcam vulnerability scanning tool, and Medusa , an open-source brute-force authentication tool .

Their attacks targeted webcams and DVRs with ports 23, 26, 554, 2323, 567, 5523, 8080, 9530 , and 56575 TCP exposed to the Internet.

The FBI advised network defenders to limit the use of devices listed in the PIN and/or isolate them from the rest of their networks to prevent compromise and lateral movement attempts following successful HiatusRAT malware attacks . It also urged system administrators and cybersecurity professionals to send suspected indications of compromise (IOC) to the FBI’s Cybercrime Complaint Center or their local FBI field office.

See also: Remcos RAT: Two new dangerous variants of the malware found

This campaign follows two other series of attacks: one that also targeted a Department of Defense server in a reconnaissance attack, and a previous wave of attacks in which more than a hundred businesses from North America, Europe, and South America had their DrayTek Vigor VPN by the HiatusRAT, which created a hidden proxy network.

HiatusRAT targets webcams and DVRs

Lumen, the cybersecurity firm that first identified HiatusRAT, said this malware is primarily used to deploy additional payloads to infected devices, turning compromised systems intoSOCKS5 proxies for command-and-control server communication.

HiatusRAT's shift to targeting cameras and gathering intelligence aligns with Chinese strategic interests, a link also highlighted in the Office of the Director of National Intelligence's 2023 annual threat assessment .

See also: Horns&Hooves: New campaign distributes NetSupport RAT & BurnsRAT

A Remote Access Trojan (RAT) is a type of malware that allows an attacker to gain unauthorized access and control over a victim’s computer. Once a RAT is installed, it operates covertly, allowing the attacker to manipulate files, monitor user activity, steal sensitive information , and even control system hardware such as cameras and microphones. Typically delivered via phishing emails, malicious downloads, or software vulnerabilities, RATs pose a significant threat to cybersecurity. Protecting against them requires strong antivirus software, careful handling of email attachments , and regular system updates to address vulnerabilities.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS