The malware library can hide among ordinary system files for years, and the new Linux backdoor uses just such an example to attack iKuai routers. The sample with zero detection level was found on VirusTotal on July 1 of this year, although the first file was downloaded from Japan on June 8.
Backdoor received the name libjson_script.so.0 and disguised as a legitimate component of the OpenWrt project. The iKuaai routers are referred to circuits to the GWID and VERSTRING parameters in system files. Both values are found in the firmware of the manufacturer, but the confirmed infections, the author did not find the analysis.
After launch, the malware prevents the appearance of the second copy, decrypts the settings and communicates with the control server. The connection runs over HTTPS without checking the certificate, and the transmitted information protects the built-in AES encryption. By default, the backdoor gets in touch once an hour.
The server sends the gate identifier, device architecture, host name, local IP address, firmware version, process number and work directory. In response, the backdoor receives an encrypted list of tasks and interval until the next request.
Operators can execute shell commands, change directories, download and run additional ELF files, create schedule tasks and cancel them. A separate command allows you to read files up to 512 KB, encode content in Base64 and send it to the control server. The results of all operations are returned as encrypted JSON messages.
Searching on the grounds of malware did not reveal any other samples, so the backdoor still looks rare. To check routers, you should search for the file libjson_script.so.0 with a hash 4e6276cc3b956c9b965b3b,7,7,7, call to 47.80.111[.129:7380 and unknown file /us/r/misc/.ruline.cache.
Backdoor received the name libjson_script.so.0 and disguised as a legitimate component of the OpenWrt project. The iKuaai routers are referred to circuits to the GWID and VERSTRING parameters in system files. Both values are found in the firmware of the manufacturer, but the confirmed infections, the author did not find the analysis.
After launch, the malware prevents the appearance of the second copy, decrypts the settings and communicates with the control server. The connection runs over HTTPS without checking the certificate, and the transmitted information protects the built-in AES encryption. By default, the backdoor gets in touch once an hour.
The server sends the gate identifier, device architecture, host name, local IP address, firmware version, process number and work directory. In response, the backdoor receives an encrypted list of tasks and interval until the next request.
Operators can execute shell commands, change directories, download and run additional ELF files, create schedule tasks and cancel them. A separate command allows you to read files up to 512 KB, encode content in Base64 and send it to the control server. The results of all operations are returned as encrypted JSON messages.
Searching on the grounds of malware did not reveal any other samples, so the backdoor still looks rare. To check routers, you should search for the file libjson_script.so.0 with a hash 4e6276cc3b956c9b965b3b,7,7,7, call to 47.80.111[.129:7380 and unknown file /us/r/misc/.ruline.cache.