New Malware Discovered Targeting Small Office/Home Office Routers

New Malware Discovered Targeting Small Office/Home Office Routers

For the third time in the past year, Black Lotus Labs–the threat research arm of Lumen Technologies– has discovered a new malware that targets small office/home office (SOHO) routers. Discovery of the malware dubbed "AVrecon" came as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued warnings about SOHO routers, including a binding operational directive in June and a cybersecurity advisory in May.

Using Lumen's global network visibility to gather a 28-day snapshot of AVrecon, Black Lotus Labs determined the malware has infiltrated more than 70,000 machines and gained persistent hold in more than 40,000 of them in 20 countries. This makes AVrecon one of the largest SOHO router-targeting botnets ever seen.

"Our network visibility enables us to see threats other researchers cannot see, and once again we have discovered a new malware that targets SOHO routers," said Michelle Lee, director of threat intelligence for Lumen Black Lotus Labs. "This time it went undetected for two years and grew to a staggering 40,000-strong botnet."

SOHO routers pose a serious threat because these devices are not always automatically patched and updated – nor are they regularly monitored – which significantly decreases the ability to detect malicious activity. With the prevalence of remote workers, corporate network defenders should take the following precautions:

  • Continue to look for attacks on weak credentials and suspicious login attempts, even when they originate from residential IP addresses.
  • Be aware that threat actors can spawn a remote shell and deploy subsequent modules.
  • Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks and begin blocking Indicators of Compromise (IoCs) with Web Application Firewalls.
  • Consumers who use SOHO routers should regularly reboot their devices and install security updates and patches where available.

Featured

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities