New Cuttlefish malware infects routers to monitor traffic for credentials
ID: 92250f27-2693-5341-8aa8-f6c1b1a3c157
STIX ID: report--92250f27-2693-5341-8aa8-f6c1b1a3c157
Feed Name: Bleeping Computer
A new router-targeting malware called Cuttlefish has been observed compromising enterprise and SOHO routers to sniff traffic for cloud-service credentials, create proxy/VPN tunnels (n2n/socks_proxy) for stealthy exfiltration, and hijack internal DNS/HTTP to redirect east-west traffic; Black Lotus Labs reports active campaigns since July 2023 concentrated in Turkey with multi-architecture builds and recommends credential hygiene, firmware updates, TLS/SSL, and device inspection/reboots as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
