In February 2023, JPCERT/CC confirmed malware attacks on routers in Japan, specifically targeting Linux routers with a new Golang RAT known as GobRAT.
The attacker exploits publicly accessible routers WEBUIs, leveraging potential vulnerabilities to infect them with the GobRAT ultimately.
After an internet-exposed router is compromised, a loader script is deployed to deliver GobRAT, which disguises itself as the Apache daemon process (apached) to avoid being detected.
How the Attack Chain Works
The attacker begins by targeting a publicly accessible router with an open WEBUI, exploits vulnerabilities through script execution, and ultimately spoils the GobRAT.
The Loader Script is a multifunctional loader, encompassing tasks like script generation, GobRAT downloading and containing a hard-coded SSH public key for the assumed backdoor.
Loader Script utilizes crontab to ensure the persistence of the file path for Start Script, while GobRAT lacks this capability, highlighting the functions of the Loader Script.
Here below, we have mentioned the functions of Loader Script:-
The Start Script code, responsible for executing GobRAT, distinguishes itself by recording the startup time in a file called restart[.]log, while also running GobRAT under the guise of a legitimate process named apached.
The Daemon Script monitors the status of the Start Script every 20 seconds. It initiates it if it is not running, indicating its potential role in handling unexpected terminations of the Start Script.
Here below, we have mentioned all the checks that the GobRAT performs:-
GobRAT utilizes TLS for data communication with its C2 server, employing a 4-byte data size indicator followed by gob serialized data, which is a Go-specific protocol used for receiving commands and transmitting command execution results.
GobRAT, targeting routers, utilizes 22 commands from the C2 server, mainly focused on communication functions like frpc, socks5, and C2 reconfiguration.
Here below we have mentioned all the major commands:-
While apart from this, Lumen Black Lotus Labs recently discovered that HiatusRAT, a malware, has been exploiting business-grade routers to spy on victims in Latin America, Europe, and North America for the past three months.
Common Security Challenges Facing CISOs? – Download Free CISO’s Guide
Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…
A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…
A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…
Every function in a security operations center, from alert triage to incident response, depends on…
ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…
Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…