Summary:
Researchers has uncovered a sophisticated and extensive cybercrime campaign involving compromised routers worldwide. This multi-year operation employs a Linux-based Remote Access Trojan (RAT) known as "AVrecon." The malware has remained undetected for over two years, enabling the threat actor to create a covert network to facilitate various criminal activities, including password spraying and digital advertising fraud. The primary targets of this campaign are small-office/home-office (SOHO) routers, making it particularly challenging to detect malicious activity due to their location outside traditional security perimeters.[/subscribe_to_unlock_form]
Summary:
Researchers has uncovered a sophisticated and extensive cybercrime campaign involving compromised routers worldwide. This multi-year operation employs a Linux-based Remote Access Trojan (RAT) known as "AVrecon." The malware has remained undetected for over two years, enabling the threat actor to create a covert network to facilitate various criminal activities, including password spraying and digital advertising fraud. The primary targets of this campaign are small-office/home-office (SOHO) routers, making it particularly challenging to detect malicious activity due to their location outside traditional security perimeters.[emaillocker id="1283"]

Attack Chain
AVrecon is a C-based RAT designed to target ARM-embedded devices, providing portability and allowing it to be compiled for different architectures. Once deployed on a compromised system, the malware performs three main actions. First is checking for other instances where AVrecon scans for existing processes on port 48102 and opens a listener on that port to detect other instances of the malware. It then kills conflicting processes to ensure its persistence. If unsuccessful, the malware is programmed to delete itself from the host entirely. Second is gathering host-based information where the RAT collects essential information about the infected machine, including kernel details, CPU, memory usage, and hostname. Subsequently, it spawns a remote shell to execute commands, download additional binaries, and configure a proxy for communication with command and control (C2) servers, and lastly building C2 parameters where AVrecon constructs parameters for communicating with C2 servers. It searches for pre-existing configurations on the infected host and uses them if available. Otherwise, it decrypts information from hardcoded configurations or other locations to establish connections with the C2. AVrecon initiates a GET request to the C2 server using the constructed parameters. The GET request contains encrypted details about the infected machine. The C2 server responds with commands and decrypted parameters, directing the malware to communicate with additional C2 servers over different ports. This tiered architecture obscures the C2 infrastructure, making it challenging to disrupt the network. The threat actor leverages the compromised machines to engage in various malicious activities. These include clicking on Facebook and Google ads to perpetrate advertising fraud and interacting with Microsoft Outlook, likely for password spraying and/or data exfiltration. This global network of compromised SOHO routers allows the cybercriminals to evade standard network-based detection tools, creating a significant risk to cybersecurity.
The AVrecon Linux-based RAT campaign poses a substantial threat to the cybersecurity landscape. Operating stealthily for over two years, the campaign has established one of the largest botnets targeting SOHO routers in recent history. The threat actor's focus on less-patched devices and the creation of a residential proxy service for money laundering make this campaign particularly challenging to detect and mitigate.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]