Chinese state-sponsored hackers exploit TP-Link routers with custom malware

TL;DR Summary
Malicious firmware has been discovered that can turn residential and small office routers into a network that relays traffic to command and control servers maintained by Chinese state-sponsored hackers. The firmware implant contains a full-featured backdoor that allows attackers to establish communications and file transfers with infected devices, remotely issue commands, and upload, download, and delete files. The malware's ultimate purpose is to relay communication between two nodes, creating a chain of nodes that will relay traffic to the command and control server, making it difficult for defenders to trace the traffic back to the C2.
- Malware turns home routers into proxies for Chinese state-sponsored hackers Ars Technica
- Hackers infect TP-Link router firmware to attack EU entities BleepingComputer
- The Dragon Who Sold His Camaro: Analyzing Custom Router Implant Check Point Research
- China's Mustang Panda Hackers Exploit TP-Link Routers for Persistent Attacks The Hacker News
- Camaro Dragon APT Group Exploits TP-Link Routers With Custom Implant Infosecurity Magazine
Reading Insights
Total Reads
1
Unique Readers
27
Time Saved
2 min
vs 3 min read
Condensed
84%
589 → 96 words
Want the full story? Read the original article
Read on Ars Technica