HiatusRAT Malware Resurfaces: Taiwan Firms and U.S. Military Under Attack

Teilen:

The threat actors behind the HiatusRAT malware have returned from their hiatus with a new wave of reconnaissance and targeting activity aimed at Taiwan-based organizations and a U.S. military procurement system.

Besides recompiling malware samples for different architectures, the artifacts are said to have been hosted on new virtual private servers (VPSs), Lumen Black Lotus Labs sagte in a report published last week.

The cybersecurity firm described the activity cluster as “brazen” and “one of the most audacious,” indicating no signs of slowing down. The identity and the origin of the threat actors are presently unknown.

Targets included commercial firms, such as semiconductor and chemical manufacturers, and at least one municipal government organization in Taiwan as well as a U.S. Department of Defense (DoD) server associated with submitting and retrieving proposals for defense contracts.

HiatusRAT was first disclosed by the cybersecurity company in March 2023 as having targeted business-grade routers to covertly spy on victims primarily located in Latin America and Europe as part of a campaign that commenced in July 2022.

As many as 100 edge networking devices globally were infected to passively collect traffic and transform them into a proxy network of command-and-control (C2) infrastructure.

HiatusRAT Malware

The latest set of attacks, observed from mid-June through August 2023, entail the use of pre-built HiatusRAT binaries specifically designed for Arm, Intel 80386, and x86-64 architectures, alongside MIPS, MIPS64, and i386.

A telemetry analysis to determine connections made to the server hosting the malware has revealed that “over 91% of the inbound connections stemmed from Taiwan, and there appeared to be a preference for Ruckus-manufactured edge devices.”

The HiatusRAT infrastructure consists of payload and reconnaissance servers, which directly communicate with the victim networks. These servers are commandeered by Tier 1 servers, which, in turn, are operated and managed by Tier 2 servers.

The attackers have been identified as using two different IP addresses 207.246.80[.]240 and 45.63.70[.]57 to connect to the DoD server on June 13 for approximately a period of two hours. 11 MB of bi-directional data is estimated to have been transferred during the period.

It’s not clear what the end goal is, but it’s suspected that the adversary may have been looking for publicly available information related to current and future military contracts for future targeting.

The targeting of perimeter assets such as routers has become something of a pattern in recent months, with China-affiliated threat actors linked to the exploitation of security flaws in unpatched Fortinet und SonicWall appliances to establish long-term persistence within target environments.

“Despite prior disclosures of tools and capabilities, the threat actor took the most minor of steps to swap out existing payload servers and carried on with their operations, without even attempting to re-configure their C2 infrastructure,” the company said.

 

(c) The Hacker News

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:48 am, Juli 3, 2025
Wetter-Symbol 13°C
L: 10° | H: 14°
klarer Himmel
Luftfeuchtigkeit: 69 %
Druck: 1026 mb
Wind: 2 mph NNE
Windböe: 5 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
10° | 14°°C 0 mm 0% 12 mph 66 % 1028 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 59 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
14° | 19°°C 1 mm 100% 11 mph 93 % 1021 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
15° | 18°°C 1 mm 100% 11 mph 88 % 1009 mb 0 mm/h
Mo. Juli 07 10:00 pm
Wetter-Symbol
13° | 16°°C 1 mm 100% 11 mph 87 % 1012 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 4 mph 66 % 1026 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
17° | 19°°C 0 mm 0% 4 mph 48 % 1027 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 5 mph 28 % 1028 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 6 mph 22 % 1026 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 12 mph 25 % 1025 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 10 mph 37 % 1027 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 7 mph 46 % 1028 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 5 mph 57 % 1028 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,201.53
2.47%
Ethereum(ETH)
€2,176.41
5.76%
Fesseln(USDT)
€0.85
0.02%
XRP(XRP)
€1.90
2.85%
Solana(SOL)
€130.16
3.07%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.143281
6.09%
Shiba Inu(SHIB)
€0.000010
5.15%
Pepe(PEPE)
€0.000008
9.50%
Nach oben scrollen