A newly discovered remote access trojan (RAT) tracked as ZuoRAT has been used to target remote workers via small office/home office (SOHO) routers across North America and Europe undetected since 2020.
The security researchers at Lumen’s Black Lotus Labs who spotted the malware stated that this highly targeted campaign’s complexity and the attackers’ tactics, techniques, and procedures (TTPs) indicates that it is the work of a state-backed threat actor.
The beginning of this campaign aligns with the shift of workers to remote work due to the COVID-19 pandemic which increased the number of SOHO routers (including ASUS, Cisco, DrayTek, and NETGEAR) used by employees to access corporate assets from home.
This gave an opportunity to threat actors to leverage at-home devices such as SOHO routers – which are widely used but rarely monitored or patched – to collect data in transit, hijack connections, and compromise devices in adjacent networks.
The malware once deployed on an unpatched router with the help of an authentication bypass exploit script, provided the attackers with in-depth network reconnaissance capabilities and traffic collection via passive network sniffing.
ZuoRAT also allows moving laterally to compromise other devices on the network and to deploy additional malicious payloads (such as Cobalt Strike beacons) using DNS and HTTP hijacking.
Two more custom trojans were delivered onto hacked devices during these attacks: a C++ based one named CBeacon targeting Windows workstations and a Go-based one dubbed GoBeacon that could likely infect Linux and Mac systems besides Windows devices.
The additional malware deployed onto systems within victims’ networks (i.e., CBeacon, GoBeacon, and Cobalt Strike) provided the threat actors with the ability to download and upload files, run arbitrary commands, hijack network traffic, inject new processes, and gain persistence on compromised devices.
Some compromised routers were also added to a botnet and used to proxy command and control (C2) traffic to hinder defenders’ detection efforts.
The researchers estimate that the campaign has so far impacted at least 80 targets. They warn that organizations should keep a close watch on SOHO devices and look for any signs of malicious activity.
In order to mitigate the threat, the firms must ensure patch planning includes routers, and confirm these devices are running the latest software available.














Comments