China-linked Hackers Target Southeast Asia's Edge Routers with Custom Malware
Article Content
- •China-linked hackers are targeting Linux-based edge routers in Southeast Asia.
- •The attack employs a custom ELF implant and a cracked Cobalt Strike Beacon.
- •The campaign has been rated critical due to its extensive impact and ongoing nature.
A China-linked hacking group is executing an espionage campaign targeting Linux-based edge routers across Southeast Asia. The attackers deploy a custom ELF implant, named router.elf, to gain deep control over network traffic. This operation utilizes a cracked Cobalt Strike Beacon on Windows systems for command-and-control, allowing extensive visibility and manipulation of downstream traffic. The campaign is rated critical in severity due to its potential to affect numerous organizations beyond the initial targets. The full scope of the impact remains unclear, but the operation is ongoing. Security experts are urging immediate attention to this threat as it poses significant risks to critical infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cobalt Strike in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a signed kernel-mode driver that enhances the malware's stealth, allowing it to hide processes and…
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their tactics to target cloud environments, specifically Azure, by hijacking high-privilege…