{"id":24721,"date":"2022-06-30T08:15:04","date_gmt":"2022-06-30T12:15:04","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=24721"},"modified":"2022-07-04T09:29:04","modified_gmt":"2022-07-04T13:29:04","slug":"zuorat-malware-targets-soho-routers-to-infiltrate-networks","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/zuorat-malware-targets-soho-routers-to-infiltrate-networks\/","title":{"rendered":"ZuoRAT Malware Targets SOHO Routers To Infiltrate Networks"},"content":{"rendered":"<p id=\"arIndex_1\" data-ar-index=\"1\">Researchers from Lumen&#8217;s Black Lotus Labs threat intelligence unit have discovered a remote access trojan (RAT) called ZuoRAT. The malware targets remote employees by exploiting vulnerabilities in unpatched small office\/home office (SOHO) routers.<\/p>\n<p id=\"arIndex_2\" data-ar-index=\"2\">The researchers estimate that at least 80 targets were affected by the campaign.<\/p>\n<p id=\"arIndex_3\" data-ar-index=\"3\">Lumen believes that the capabilities of the malware suggest that it was the work of a highly sophisticated actor.<\/p>\n<p id=\"arIndex_4\" data-ar-index=\"4\">These capabilities include &#8220;gaining access to SOHO devices of different makes and models, collecting host and LAN information to inform targeting, sampling and hijacking network communications to gain potentially persistent access to in-land devices, and intentionally stealth C2 infrastructure leveraging multistage siloed router to router communications.&#8221;<\/p>\n<p id=\"arIndex_5\" data-ar-index=\"5\">Lumen admits, however, that it has limited insight into the broader capabilities of the actor, but Lumen&#8217;s researchers are &#8220;confident&#8221; that the elements it is tracking are part of a broader campaign.<\/p>\n<p id=\"arIndex_6\" data-ar-index=\"6\">SOHO router manufacturers compromised include ASUS, Cisco, DrayTek, and Netgear.<\/p>\n<p id=\"arIndex_7\" data-ar-index=\"7\">The sources for this piece include an article in <a href=\"https:\/\/www.zdnet.com\/article\/this-sophisticated-malware-is-targeting-routers-to-break-into-networks\/\" target=\"_blank\" rel=\"noopener\">ZDNet<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers from Lumen&#8217;s Black Lotus Labs threat intelligence unit have discovered a remote access trojan (RAT) called ZuoRAT. The malware targets remote employees by exploiting vulnerabilities in unpatched small office\/home office (SOHO) routers. The researchers estimate that at least 80 targets were affected by the campaign. Lumen believes that the capabilities of the malware suggest [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[34,16,9],"tags":[388,393],"class_list":["post-24721","post","type-post","status-publish","format-standard","hentry","category-artificial-intelligence","category-security","category-todays-news","tag-privacy-security","tag-security-strategies"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/24721","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=24721"}],"version-history":[{"count":2,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/24721\/revisions"}],"predecessor-version":[{"id":24723,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/24721\/revisions\/24723"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=24721"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=24721"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=24721"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}