Security News > 2023 > March > DrayTek VPN routers hacked with new malware to steal data, evade detection

An ongoing hacking campaign called 'Hiatus' targets DrayTek Vigor router models 2960 and 3900 to steal data from victims and build a covert proxy network.
DrayTek Vigor devices are business-class VPN routers used by small to medium-size organizations for remote connectivity to corporate networks.
The new hacking campaign, which started in July 2022 and is still ongoing, relies on three components: a malicious bash script, a malware named "HiatusRAT," and the legitimate 'tcpdump,' used to capture network traffic flowing over the router.
At this time, the researchers are unable to determine how the DrayTek routers were initially compromised.
The purpose of the SOCKS proxy is to forward data from other infected machines through the breached router, obfuscating network traffic and mimicking legitimate behavior.
Black Lotus' scans revealed that as of mid-February 2023, about 4,100 vulnerable DrayTek routers are exposed on the internet, so compromising only 2.4% indicates mannerism.
News URL
Related news
- Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and Malware (source)
- FBI: End-of-life routers hacked for cybercrime proxy networks (source)
- Police dismantles botnet selling hacked routers as residential proxies (source)
- RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer (source)