'Cuttlefish' Zero-Click Malware Steals Private Cloud Data
ID: bdeee686-6d5f-5584-b862-aa1db4da476b
STIX ID: report--bdeee686-6d5f-5584-b862-aa1db4da476b
Feed Name: Dark Reading
Date Published: 2024-05-01
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Black Lotus Labs discovered a previously unseen modular malware named “Cuttlefish” that compromises SOHO and enterprise routers to sniff traffic, hijack DNS/HTTP for private IP connections, and steal authentication credentials—especially for cloud services—by tunneling exfiltration through compromised routers. The campaign has been active since at least July, with the majority of infections (~600 unique IPs) in Turkey, supports multiple architectures, is configured via C2-delivered rules to target specific traffic patterns, and shows code similarities to HiatusRAT; the researchers provide IoCs and mitigation advice for both enterprise defenders and consumer SOHO operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
