Summary:
Since January 2023, a series of advanced and precise attacks targeting European foreign affairs entities has been attributed to the Chinese state-sponsored group recognized as Mustang Panda. Through analysis, it has been discovered that a specialized firmware implant has been developed specifically for TP-Link routers. The discovered implant comprises various malicious elements, including a bespoke backdoor called 'Horse Shell.' This backdoor empowers the attackers to establish continuous access, construct anonymous infrastructure, and facilitate lateral movement within compromised networks. The implant's design is independent of firmware, allowing its components to be incorporated into firmware from different vendors. A threat group referred to by various aliases such as Camaro Dragon, BASIN, Bronze President, Earth Preta, HoneyMyte, RedDelta, and Red Lich is being monitored by an Israeli cybersecurity company.[/subscribe_to_unlock_form]
Summary:
Since January 2023, a series of advanced and precise attacks targeting European foreign affairs entities has been attributed to the Chinese state-sponsored group recognized as Mustang Panda. Through analysis, it has been discovered that a specialized firmware implant has been developed specifically for TP-Link routers. The discovered implant comprises various malicious elements, including a bespoke backdoor called 'Horse Shell.' This backdoor empowers the attackers to establish continuous access, construct anonymous infrastructure, and facilitate lateral movement within compromised networks. The implant's design is independent of firmware, allowing its components to be incorporated into firmware from different vendors. A threat group referred to by various aliases such as Camaro Dragon, BASIN, Bronze President, Earth Preta, HoneyMyte, RedDelta, and Red Lich is being monitored by an Israeli cybersecurity company.[emaillocker id="1283"]
The specific technique utilized for deploying the manipulated firmware images on the compromised routers remains unidentified, along with its purpose and extent of involvement in real-world attacks. There is a suspicion that the initial access might have been obtained by exploiting recognized security vulnerabilities or by employing brute-force methods to crack devices using default or easily predictable passwords. It has been established that the Horse Shell implant, built on C++ programming language, grants attackers the capability to execute unrestricted shell commands, transfer files to and from the router, and facilitate communication relay between two distinct clients. Moreover, the modified firmware conceals the option for users to flash an alternative image through the router's web interface, thereby limiting their ability to make changes or updates.
The router backdoor is suspected of targeting various devices within residential and home networks, indicating that the compromised routers are being enlisted into a mesh network. This mesh network aims to establish a "chain of nodes" connecting primary infections to a legitimate command-and-control infrastructure. By employing a SOCKS tunnel to relay communications between infected routers, the objective is to enhance anonymity and unknown the identity of the final server. Each node in the chain possesses knowledge solely about the preceding and succeeding nodes, ensuring a layered level of information concealment. The utilized methods obfuscate the source and destination of the traffic, similar to the workings of TOR. This significantly increases the difficulty of detecting the extent of the attack and impeding its progress. Even if one node in the chain is compromised or deactivated, the attacker can maintain communication with the command-and-control (C2) server by redirecting traffic through an alternate node within the chain.
However, it is worth noting that this is not the initial instance in which threat actors affiliated with China have utilized compromised routers as a network to fulfil their strategic goals. The revelation serves as another illustration of the persistent trend among Chinese threat actors to exploit network devices that are accessible via the internet and manipulate their underlying software or firmware.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/05/chinas-mustang-panda-hackers-exploit-tp.html
[/emaillocker]