Chinese Malware Can Turn Your WiFi Routers Into Cyber Spies

China is famous for its viruses. This time Chinese state-sponsored malware found which can corrupt domestic routers & make them cyber spies.

A recent discovery by Check Point Research has unveiled a hair-raising cyber threat in the form of Chinese state-sponsored malware. 

This malicious firmware has the capability to transform residential and small office routers into covert networks, effectively turning innocent routers into cyber spies.

The firmware implant goes beyond the typical cyber threat. It is a highly sophisticated menace that includes a comprehensive backdoor, allowing attackers to establish communication, transfer files, and remotely execute commands on compromised devices. 

The malware is disguised within firmware images for TP-Link routers, displaying a meticulous effort to ensure compatibility with various router models, making it easy for attackers to adapt and expand their reach.

The malware operates as a relay, covertly transmitting traffic between infected targets and the attackers’ command and control servers. 

This cleverly obscures the origins and destinations of communication, making it difficult to trace back to the cyber espionage activities. 

Through further investigation, Check Point Research traced the control infrastructure to a threat actor known as Mustang Panda, which is allegedly associated with the Chinese government, according to security firms Avast and ESET.

Rather than specific targeting, the malware follows a strategy of infection for obfuscation. The compromised routers act as intermediate nodes in a chain, creating a network between primary infections and the actual command and control system. This allows the attackers to maintain control and communicate without raising suspicion.

The implant, named ‘Horse Shell’ internally, comprises three key functions. 

Firstly, it includes a remote shell that enables the execution of commands on the infected device. 

Secondly, it facilitates file transfer, allowing both uploading and downloading of files. 

Lastly, it incorporates SOCKS5 functionality, a protocol used for proxying TCP connections and forwarding UDP packets, enabling data exchange between infected devices.

The ultimate objective of the malware is to create a chain of shadows, leveraging the SOCKS5 functionality to establish encrypted connections between infected devices. 

This approach effectively masks the origin, destination, and purpose of the cyber espionage. 

Even if one node in the chain is disrupted, the attacker can route traffic through an alternate node to maintain communication with the command and control servers.

The discovery of this Chinese state-sponsored malware highlights the alarming potential of home WiFi routers being turned into cyber spies. 

The sophistication and adaptability of the malware, along with its obfuscation techniques, pose a significant threat to cybersecurity. 

Also Read:- Lava Agni 2 5G Launched In India With 3D Dual Curved AMOLED Display

It underscores the need for robust security measures and heightened awareness to protect against such state-sponsored cyber espionage activities.

The Techy Guy

Pranjal Shah covers tech news at India Observers. He is very passionate about innovation, the internet world and gadgets. He loves to share technology-based niche news articles.

Recent Posts

Jaishankar Rules Out Bilateral Talks with Pakistan at SCO Summit

External Affairs Minister of India, S Jaishankar is set to visit Pakistan in mid-October to…

October 5, 2024

Dubai Hosts Thrilling South Africa-West Indies Clash in T20 World Cup

ICC Women’s T20 World Cup 2024 kicked off in Dubai with an exciting face-off between…

October 4, 2024

Kick 2 Is Happening! Sajid Nadiadwala Drops First Look of Salman Khan’s Iconic Return

Salman Khan fans have something big to celebrate! Producer Sajid Nadiadwala has officially announced the…

October 4, 2024

Power Outage in Chennai on October 4: Is Your Area on the List?

Chennai will have a power cut on October 4, 2024, as reported by various news…

October 4, 2024

Google Enhances Search Engine with AI-Powered Video and Image Search

As part of the next phase in developing the company’s artificial intelligence, Google is to…

October 4, 2024

OpenAI Secures $6.6 Billion in Funding to Boost AI Research

According to the news sources like Reuters, OpenAI has successfully raised $6.6 billion in new…

October 3, 2024

This website uses cookies.

Read More