The Federal Bureau of Investigation (FBI) has issued a Private Industry Notification (PIN) alerting cybersecurity professionals and system administrators about a new threat targeting web cameras and digital video recorders (DVRs).
The malware, known as HiatusRAT, is actively scanning for vulnerabilities in these devices, particularly those of Chinese origin.
HiatusRAT, a Remote Access Trojan (RAT), has been in operation since July 2022. This sophisticated malware allows cybercriminals to take control of targeted devices remotely.
Initially focused on outdated network edge devices, the Hiatus campaign has expanded its scope to include a range of organizations in Taiwan and even reconnaissance against a U.S. government server used for defense contract proposals.
Free Webinar on Best Practices for API vulnerability & Penetration Testing: Free Registration
In March 2024, HiatusRAT actors launched a widespread scanning campaign targeting Internet of Things (IoT) devices across the United States, Australia, Canada, New Zealand, and the United Kingdom.
The attackers are specifically looking for vulnerabilities in web cameras and DVRs, including several critical security flaws that manufacturers have not yet patched.
The FBI notification highlights that the cybercriminals are particularly interested in Xiongmai and Hikvision devices with telnet access.
They employ various tools in their attacks, including Ingram, a webcam-scanning tool available on GitHub, and Medusa, an open-source brute-force authentication cracking tool.
Several vulnerabilities are being exploited by the HiatusRAT actors, including:
The FBI strongly recommends that organizations limit the use of affected devices or isolate them from the rest of their network. Additionally, the bureau advises implementing best cybersecurity practices, including:
The FBI encourages organizations to report any suspected indications of compromise to their local FBI field office or the Internet Crime Complaint Center.
As cyber threats continue to evolve, staying vigilant and implementing robust security measures remains crucial for protecting sensitive information and maintaining the integrity of network infrastructure.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…