• Book Dewayne Hart
  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
  • Speaker Bio
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
Facebook-f Linkedin-in Youtube X-twitter Globe
Order books

New Cuttlefish Malware Hijacks Router Connections, Sniffs for Cloud Credentials

Posted on May 4, 2024 by admin

[ad_1]

May 02, 2024NewsroomCyber Espionage / Network Security

Cuttlefish Malware

A new malware called Cuttlefish is targeting small office and home office (SOHO) routers with the goal of stealthily monitoring all traffic through the devices and gather authentication data from HTTP GET and POST requests.

“This malware is modular, designed primarily to steal authentication material found in web requests that transit the router from the adjacent local area network (LAN),” the Black Lotus Labs team at Lumen Technologies said in a report published today.

“A secondary function gives it the capacity to perform both DNS and HTTP hijacking for connections to private IP space, associated with communications on an internal network.”

There is source code evidence suggesting overlaps with another previously known activity cluster called HiatusRAT, although no shared victimology has been observed to date. It’s said that these two operations are running concurrently.

Cybersecurity

Cuttlefish has been active since at least July 27, 2023, with the latest campaign running from October 2023 through April 2024 and predominantly infecting 600 unique IP addresses associated with two Turkish telecom providers.

The exact initial access vector used to compromise networking equipment is unclear. However, a successful foothold is followed by the deployment of a bash script that gathers host data, such as the contents of /etc, running processes, active connections, and mounts, and exfiltrates the details to an actor-controlled domain (“kkthreas[.]com/upload”).

Cuttlefish Malware

It subsequently downloads and executes the Cuttlefish payload from a dedicated server depending on the router architecture (e.g., Arm, i386, i386_i686, i386_x64, mips32, and mips64).

A noteworthy aspect is that the passive sniffing of the network packets is primarily designed to single out authentication data associated with public cloud-based services such as Alicloud, Amazon Web Services (AWS), Digital Ocean, CloudFlare, and BitBucket by creating an extended Berkeley Packet Filter (eBPF).

This functionality is governed based on a ruleset that dictates the malware to either hijack traffic destined to a private IP address, or initiate a sniffer function for traffic heading to a public IP in order to steal credentials if certain parameters are met.

Cybersecurity

The hijack rules, for their part, are retrieved and updated from a command-and-control (C2) server set up for this purpose after establishing a secure connection to it using an embedded RSA certificate.

The malware is also equipped to act as a proxy and a VPN to transmit the captured data through the infiltrated router, thereby allowing the threat actors to use the stolen credentials to access targeted resources.

“Cuttlefish represents the latest evolution in passive eavesdropping malware for edge networking equipment […] as it combines multiple attributes,” the cybersecurity firm said.

“It has the ability to perform route manipulation, hijack connections, and employs passive sniffing capability. With the stolen key material, the actor not only retrieves cloud resources associated with the targeted entity but gains a foothold into that cloud ecosystem.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



[ad_2]

Recent Posts

  • Cybersecurity Leadership in 2026: Executive Decisions that Drive Resilience and Growth
  • Implementing a Hacker’s Mindset: Build a Security Culture That Hunts, Learns, and Wins
  • The Future of Cybersecurity Leadership: Integrating Military Discipline and Strategic Thinking
  • Prioritize to Win: Optimizing Cyber Risk for Maximum Business Impact
  • Lead Before the Breach: How Executives Prevent AI-Driven Cyber Attacks

Recent Comments

No comments to show.

Archives

  • February 2026
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023

Categories

  • Cyber News
  • Uncategorized

Book Dewayne Hart for your next event

  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
Facebook-f Linkedin-in Youtube X-twitter Globe
© 2025 Dewayne Hart | Cybersecurity Leadership & Innovation