Chinese APT Hacking Routers to Build Espionage Infrastructure

Chinese APT Hacking Routers to Build Espionage Infrastructure

A China-linked APT has developed an extensive relay network of over 1,000 compromised nodes, mainly targeting industries across the US and Southeast Asia for espionage. The campaign involves infecting unpatched routers with a stealthy backdoor called ShortLeash, enabling long-term covert access. #LapDogs #UAT-5918

Keypoints

  • The threat actor has built an ORB network of over 1,000 malicious nodes for espionage activities.
  • The campaign targets industries such as IT, media, networking, and real estate in multiple countries.
  • Infected devices include Ruckus Wireless access points and Buffalo routers, vulnerable due to outdated services.
  • The operation appears to be linked to Chinese APT group UAT-5918, connected to other Chinese espionage activities.
  • The malware uses custom backdoors with fake TLS certificates and exploits known vulnerabilities for initial access.

Read More: https://www.securityweek.com/chinese-apt-hacking-routers-to-build-espionage-infrastructure/