Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Young Thug YSL Records Surprise-Drop ‘Slime Language 3’ Double Album

    August 29, 2026

    How the Strait of Hormuz crisis forced Asia to rewrite its oil and gas energy strategy

    August 29, 2026

    Treasury Sec. Scott Bessent Schools Elizabeth Warren – Offers Her ‘Foreign Exchange for Dummies’ * The Gateway Pundit * by Mike LaChance

    August 29, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»A New, Remarkably Sophisticated Malware Is Attacking Routers
    Technology

    A New, Remarkably Sophisticated Malware Is Attacking Routers

    By AdminJuly 1, 2022
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    A New, Remarkably Sophisticated Malware Is Attacking Routers


    An unusually advanced hacking group has spent almost two years infecting a wide range of routers in North America and Europe with malware that takes full control of connected devices running Windows, macOS, and Linux, researchers reported on June 28.

    So far, researchers from Lumen Technologies’ Black Lotus Labs say they’ve identified at least 80 targets infected by the stealthy malware, including routers made by Cisco, Netgear, Asus, and DrayTek. Dubbed ZuoRAT, the remote access Trojan is part of a broader hacking campaign that has existed since at least the fourth quarter of 2020 and continues to operate.

    A High Level of Sophistication

    The discovery of custom-built malware written for the MIPS architecture and compiled for small-office and home-office routers is significant, particularly given its range of capabilities. Its ability to enumerate all devices connected to an infected router and collect the DNS lookups and network traffic they send and receive and remain undetected is the hallmark of a highly sophisticated threat actor.

    “While compromising SOHO routers as an access vector to gain access to an adjacent LAN is not a novel technique, it has seldom been reported,” Black Lotus Labs researchers wrote. “Similarly, reports of person-in-the-middle style attacks, such as DNS and HTTP hijacking, are even rarer and a mark of a complex and targeted operation. The use of these two techniques congruently demonstrated a high level of sophistication by a threat actor, indicating that this campaign was possibly performed by a state-sponsored organization.”

    The campaign comprises at least four pieces of malware, three of them written from scratch by the threat actor. The first piece is the MIPS-based ZuoRAT, which closely resembles the Mirai internet-of-things malware that achieved record-breaking distributed denial-of-service attacks that crippled some Internet services for days. ZuoRAT often gets installed by exploiting unpatched vulnerabilities in SOHO devices.

    Once installed, ZuoRAT enumerates the devices connected to the infected router. The threat actor can then use DNS hijacking and HTTP hijacking to cause the connected devices to install other malware. Two of those malware pieces—dubbed CBeacon and GoBeacon—are custom-made, with the first written for Windows in C++ and the latter written in Go for cross-compiling on Linux and macOS devices. For flexibility, ZuoRAT can also infect connected devices with the widely used Cobalt Strike hacking tool.

    ZuoRAT can pivot infections to connected devices using one of two methods:

    • DNS hijacking, which replaces the valid IP addresses corresponding to a domain such as Google or Facebook with a malicious one operated by the attacker.
    • HTTP hijacking, in which the malware inserts itself into the connection to generate a 302 error that redirects the user to a different IP address.

    Intentionally Complex

    Black Lotus Labs said the command-and-control infrastructure used in the campaign is intentionally complex in an attempt to conceal what’s happening. One set of infrastructure is used to control infected routers, and another is reserved for the connected devices if they’re later infected.

    The researchers observed routers from 23 IP addresses with a persistent connection to a control server that they believe was performing an initial survey to determine if the targets were of interest. A subset of those 23 routers later interacted with a Taiwan-based proxy server for three months. A further subset of routers rotated to a Canada-based proxy server to obfuscate the attacker’s infrastructure.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleWest Virginia v EPA: What does the new US Supreme Court ruling mean for carbon emissions?
    Next Article Hannity: Democrats and the media mob are focused on one thing only

    RELATED POSTS

    Nvidia CEO Jensen Huang Took a Call From Donald Trump in the Middle of an All-Hands

    August 29, 2026

    More Americans oppose police license plate cameras than support them: survey

    August 28, 2026

    A Judge Has Blocked the Pentagon’s Attempt to Blacklist Anthropic

    August 28, 2026

    Google’s AI Mode can now track flight prices, help book hotels, and more

    August 27, 2026

    How to See the Partial Lunar Eclipse and Blood Moon on August 27

    August 27, 2026

    The Music Business Is Changing Again — FENIX360 Wants Artists to Lead What Comes Next

    August 26, 2026
    latest posts

    Young Thug YSL Records Surprise-Drop ‘Slime Language 3’ Double Album

    Young Thug and his YSL Records surprise-dropped the Slime Language 3 double album late Friday…

    How the Strait of Hormuz crisis forced Asia to rewrite its oil and gas energy strategy

    August 29, 2026

    Treasury Sec. Scott Bessent Schools Elizabeth Warren – Offers Her ‘Foreign Exchange for Dummies’ * The Gateway Pundit * by Mike LaChance

    August 29, 2026

    Greg Abbott orders pause on Flock Safety funding amid privacy concerns

    August 29, 2026

    Nvidia CEO Jensen Huang Took a Call From Donald Trump in the Middle of an All-Hands

    August 29, 2026

    Where are all the aliens? A new book explores possible answers

    August 29, 2026

    4 Months Later, Oliver Queen’s Green Arrow Clone Is DC’s Biggest Summer Mystery

    August 29, 2026
    Categories
    • Books (1,457)
    • Business (6,360)
    • Events (70)
    • Film (6,295)
    • Lifestyle (4,368)
    • Music (6,422)
    • Politics (6,345)
    • Science (5,712)
    • Technology (6,293)
    • Television (5,983)
    • Uncategorized (9)
    • US News (6,348)
    popular posts

    Michael Bolton Says He Underwent Surgery For A Brain Tumor, Cancels Shows

    The pop-rock ballad hitmaker required “immediate surgery,” he said. Original Source Link

    NFL to vote on allowing private equity to own teams

    August 27, 2024

    Human Embryo Implantation Revealed in First-Ever 3D Images

    August 16, 2025

    Atlus Doesn’t Know What To Do With Persona

    May 31, 2022
    Archives
    Browse By Category
    • Books (1,457)
    • Business (6,360)
    • Events (70)
    • Film (6,295)
    • Lifestyle (4,368)
    • Music (6,422)
    • Politics (6,345)
    • Science (5,712)
    • Technology (6,293)
    • Television (5,983)
    • Uncategorized (9)
    • US News (6,348)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Where are all the aliens? A new book explores possible answers

    August 29, 2026

    4 Months Later, Oliver Queen’s Green Arrow Clone Is DC’s Biggest Summer Mystery

    August 29, 2026

    Jelly Roll Shocks With Alleged Romance Bunnie Gets Groove Back

    August 29, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT