Cuttlefish Malware is Far From Being Cute, It's a Very Dangerous Computer Threat

malware warning

The Cuttlefish malware, despite its seemingly harmless name, poses a significant threat to small office and home office (SOHO) routers. Its primary objective is to clandestinely monitor network traffic passing through these devices and gather authentication data from HTTP GET and POST requests. According to a report by the Black Lotus Labs team at Lumen Technologies, Cuttlefish operates as a modular malware, with a primary focus on stealing authentication information transmitted through the router's local area network (LAN). Additionally, it has the capability to perform DNS and HTTP hijacking for connections to private IP spaces within an internal network.

There are indications that Cuttlefish shares similarities with another known malware called HiatusRAT, although there haven't been observed cases of shared victimology as of yet. Cuttlefish has been active since at least July 27, 2023, with its latest campaign running from October 2023 through April 2024, predominantly affecting 600 unique IP addresses associated with two Turkish telecom providers.

The initial access vector used by Cuttlefish to compromise networking equipment remains unclear. However, once it gains a foothold, it deploys a bash script to gather host data and exfiltrate it to an actor-controlled domain. Subsequently, it downloads and executes the Cuttlefish payload tailored to the router's architecture. Notably, Cuttlefish focuses on passive network packet sniffing to target authentication data associated with public cloud-based services such as Alicloud, Amazon Web Services (AWS), Digital Ocean, CloudFlare, and BitBucket, utilizing an extended Berkeley Packet Filter (eBPF).

The malware's functionality is governed by a ruleset retrieved from a command-and-control (C2) server, allowing it to hijack traffic destined for private IP addresses or initiate a sniffer function for traffic headed to public IPs to steal credentials. Furthermore, Cuttlefish can act as a proxy and VPN to transmit captured data through the compromised router, enabling threat actors to access targeted resources using stolen credentials.

In summary, Cuttlefish represents a sophisticated evolution in passive eavesdropping malware for edge networking equipment, combining route manipulation, connection hijacking, and passive sniffing capabilities. Its ability to steal authentication data not only grants access to cloud resources but also establishes a foothold within the targeted entity's cloud ecosystem, posing a significant threat to cybersecurity.

May 2, 2024

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.