An information security firm has published details of a large-scale malware attack in October last year that resulted in over 600,000 small and home office (SOHO) gateways being rendered permanently inoperable in just 72 hours, with the devices needing to be physically replaced.
Researchers at security vendor Lumen Technologies' Black Lotus Labs said the attack using the 'Chalubo' remote access trojan (RAT), first found in 2018, was used to deploy a destructive payload at the end of October last year.
Residential and small office broadband routers connected to the Internet are often not patched against security vulnerabilities, leaving them as sitting ducks for attackers to exploit in large numbers. Regularly rebooting routers, and installing any available security updates may help to mitigate against vulnerabilities, along with updating the devices themselves as they become old and no longer supported.
Black Lotus Labs said the 'Chalubo" RAT obfuscated its presence and activity while on the routers, by removing all files from disks to run in memory only. It would also assume a random process name that was already present on the router, and encrypted all communications with the attacker's command and control (C2) server.
How exactly the attacker got initial access on the routers is not yet know, but Black Lotus Labs believes it was done through exploiting weak login credentials, or via an exposed device administrative interface. The modular malware would retrieve and run a destructive payload, which Black Lotus Labs has not been able to recover as 'Chalubo' and the scripts it deployed would delete all traces of malicious code from the routers.
The attacked routers were from United States company ActionTec, and France's Sagemcom. A single autonomous system number (ASN) network assigned to an internet provider that focused on rural customers was targeted by the attacker, the researchers said.
Why that network was attacked is not known. Black Lotus Labs pointed out the attack was highly concerning, and likely to have caused the ISP customers plenty of grief.
A sizeable portion of this ISP’s service area covers rural or underserved communities; places where residents may have lost access to emergency services, farming concerns may have lost critical information from remote monitoring of crops during the harvest, and health care providers cut off from telehealth or patients’ records. Needless to say, recovery from any supply chain disruption takes longer in isolated or vulnerable communities.
In March this year, Black Lotus Labs said it had unearthed another malware campaign targeting 6000 routers made by Taiwanese IT giant ASUS. The devices were old, end-of-life, and were attacked with 'TheMoon' malware which has been in existence since 2014.
Compromised routers were used as part of a botnet that provided an anonymising proxy service.
We welcome your comments below. If you are not already registered, please register to comment
Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.