New Malware Discovered Targeting Small Office/Home Office Routers

New Malware Discovered Targeting Small Office/Home Office Routers

For the third time in the past year, Black Lotus Labs–the threat research arm of Lumen Technologies– has discovered a new malware that targets small office/home office (SOHO) routers. Discovery of the malware dubbed "AVrecon" came as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued warnings about SOHO routers, including a binding operational directive in June and a cybersecurity advisory in May.

Using Lumen's global network visibility to gather a 28-day snapshot of AVrecon, Black Lotus Labs determined the malware has infiltrated more than 70,000 machines and gained persistent hold in more than 40,000 of them in 20 countries. This makes AVrecon one of the largest SOHO router-targeting botnets ever seen.

"Our network visibility enables us to see threats other researchers cannot see, and once again we have discovered a new malware that targets SOHO routers," said Michelle Lee, director of threat intelligence for Lumen Black Lotus Labs. "This time it went undetected for two years and grew to a staggering 40,000-strong botnet."

SOHO routers pose a serious threat because these devices are not always automatically patched and updated – nor are they regularly monitored – which significantly decreases the ability to detect malicious activity. With the prevalence of remote workers, corporate network defenders should take the following precautions:

  • Continue to look for attacks on weak credentials and suspicious login attempts, even when they originate from residential IP addresses.
  • Be aware that threat actors can spawn a remote shell and deploy subsequent modules.
  • Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks and begin blocking Indicators of Compromise (IoCs) with Web Application Firewalls.
  • Consumers who use SOHO routers should regularly reboot their devices and install security updates and patches where available.

Featured

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.