logo

New Cuttlefish malware infects routers to monitor traffic for credentials

ID: 92250f27-2693-5341-8aa8-f6c1b1a3c157

STIX ID: report--92250f27-2693-5341-8aa8-f6c1b1a3c157

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A new router-targeting malware called Cuttlefish has been observed compromising enterprise and SOHO routers to sniff traffic for cloud-service credentials, create proxy/VPN tunnels (n2n/socks_proxy) for stealthy exfiltration, and hijack internal DNS/HTTP to redirect east-west traffic; Black Lotus Labs reports active campaigns since July 2023 concentrated in Turkey with multi-architecture builds and recommends credential hygiene, firmware updates, TLS/SSL, and device inspection/reboots as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.