logo

China-Linked Hackers Target Southeast Asian Edge Routers With Custom Linux Implant

ID: b6fcd384-6d02-590e-92a4-e56d4c6cd561

STIX ID: report--b6fcd384-6d02-590e-92a4-e56d4c6cd561

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Tushar Subhra Dutta

...
...

A China-linked advanced persistent threat is actively targeting edge routers across Southeast Asia by installing a custom Linux implant (router.elf) that establishes encrypted C2 via HTTPS and DNS-over-HTTPS, adds iptables and ipset rules to redirect DNS traffic, and deploys a secondary backdoor (client_rc_start). The same actor uses DLL sideloading to drop a Cobalt Strike Beacon (version.dll) on Windows endpoints; both toolsets share identical C2 infrastructure, timing, and metadata. The report includes detailed IoCs (hashes, domains, IPs, URI patterns, cookie markers) and urgent remediation guidance to audit routers for unauthorized firewall/DNS rules, scan for the listed artifacts, and enforce firmware integrity and MFA for device management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.