Security News > 2023 > March > DrayTek VPN routers hacked with new malware to steal data, evade detection

An ongoing hacking campaign called 'Hiatus' targets DrayTek Vigor router models 2960 and 3900 to steal data from victims and build a covert proxy network.
DrayTek Vigor devices are business-class VPN routers used by small to medium-size organizations for remote connectivity to corporate networks.
The new hacking campaign, which started in July 2022 and is still ongoing, relies on three components: a malicious bash script, a malware named "HiatusRAT," and the legitimate 'tcpdump,' used to capture network traffic flowing over the router.
At this time, the researchers are unable to determine how the DrayTek routers were initially compromised.
The purpose of the SOCKS proxy is to forward data from other infected machines through the breached router, obfuscating network traffic and mimicking legitimate behavior.
Black Lotus' scans revealed that as of mid-February 2023, about 4,100 vulnerable DrayTek routers are exposed on the internet, so compromising only 2.4% indicates mannerism.
News URL
Related news
- Malware botnets exploit outdated D-Link routers in recent attacks (source)
- New FireScam Android malware poses as RuStore app to steal data (source)
- FireScam Android Malware Poses as Telegram Premium to Steal Data and Control Devices (source)
- FBI Deletes PlugX Malware from 4,250 Hacked Computers in Multi-Month Operation (source)
- Unsecured Tunneling Protocols Expose 4.2 Million Hosts, Including VPNs and Routers (source)
- IPany VPN breached in supply-chain attack to push custom malware (source)
- Stealthy 'Magic Packet' malware targets Juniper VPN gateways (source)
- Juniper enterprise routers backdoored via “magic packet” malware (source)