logo

'Cuttlefish' Zero-Click Malware Steals Private Cloud Data

ID: bdeee686-6d5f-5584-b862-aa1db4da476b

STIX ID: report--bdeee686-6d5f-5584-b862-aa1db4da476b

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-05-01

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Black Lotus Labs discovered a previously unseen modular malware named “Cuttlefish” that compromises SOHO and enterprise routers to sniff traffic, hijack DNS/HTTP for private IP connections, and steal authentication credentials—especially for cloud services—by tunneling exfiltration through compromised routers. The campaign has been active since at least July, with the majority of infections (~600 unique IPs) in Turkey, supports multiple architectures, is configured via C2-delivered rules to target specific traffic patterns, and shows code similarities to HiatusRAT; the researchers provide IoCs and mitigation advice for both enterprise defenders and consumer SOHO operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.