Skip to main content

DrayTek VPN routers hacked with new malware to steal data, evade detection

  • March 6, 2023
  • 1 reply
  • 5 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

March 6, 2023 By Bill Toulas

 

An ongoing hacking campaign called 'Hiatus' targets DrayTek Vigor router models 2960 and 3900 to steal data from victims and build a covert proxy network.

DrayTek Vigor devices are business-class VPN routers used by small to medium-size organizations for remote connectivity to corporate networks.

The new hacking campaign, which started in July 2022 and is still ongoing, relies on three components: a malicious bash script, a malware named "HiatusRAT," and the legitimate 'tcpdump,' used to capture network traffic flowing over the router.

 

Hiatus victims heatmap                                      HiatusRAT victims until February 20, 2023 (Lumen)

 

>> Full Article <<

1 reply

russell.harris
Popular Voice
Forum|alt.badge.img+5

Will forward this on as I know we supports some drayteks. 
 

Thanks for posting