Researchers studying cybersecurity have shown that a threat actor using the moniker ViciousTrap has infiltrated approximately 5,300 distinct network edge devices in 84 countries, transforming them into a network akin to a honeypot.
A severe security weakness affecting Cisco Small Business routers RV016, RV042, RV042G, RV082, RV320, and RV325 (CVE-2023-20118) has been used by the threat actor to force them all into a series of honeypots. Macau is home to 850 compromised devices, which accounts for the majority of the infections.
In an analysis released Thursday, Sekoia stated that the infection chain entails the use of a shell script called NetGhost, which sends incoming traffic from particular ports of the compromised router to an infrastructure that resembles a honeypot and is controlled by the attacker, enabling them to intercept network flows.
It’s important to note that the French cybersecurity firm already linked the exploitation of CVE-2023-20118 to another botnet known as PolarEdge read more about ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5300 Compromised Devices.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
