Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ViciousTrap

Also known as: tracked as, CVE-2023-39780, to execute system commands, CVE-2023-20118, Sift

Description

ViciousTrap emerged as a sophisticated threat actor that leveraged newly discovered vulnerabilities – CVE‑2023‑20118 in Cisco Small Business routers and CVE‑2023‑39780 in ASUS router firmware – to gain privileged access on hundreds of thousands of IoT and edge devices worldwide. Once compromised, the attackers deploy the lightweight NetGhost shell script to manipulate port forwarding rules, effectively turning each device into a man‑in‑the‑middle proxy that can intercept traffic destined for legitimate destinations. The cohort shares and re‑uses tooling with other botnets such as PolarEdge, evidencing an ecosystem of off‑the‑shelf components. Persistence is achieved by writing backdoors to non‑volatile memory, injecting attacker public keys into the SSH configuration under custom ports (e.g., TCP/53282), and disabling native logging features so that forensic footprints are minimized. The botnet’s scale – over 5,500 compromised devices – enables a broad surveillance network with high covertness. Operationally, ViciousTrap focuses on sectors where prolonged, low‑profiling observation can yield strategic intelligence, while the use of diverse vendor devices dilutes attribution and complicates incident response. Its attacks begin via brute‑force credential attempts followed by exploitation of command‑injection vulnerabilities, creating a funnel that turns unmanaged routers into stealthy reconnaissance assets.

Goals & Targeting

Targeted Sectors

Government
Manufacturing
Critical infrastructure
Energy

Targeted Countries / Regions

CN
US
RU
PK
TW

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 7 hours ago

Executive Summary

ViciousTrap has compromised thousands of edge routers across more than 80 countries using the zero‑day CVE‑2023‑20118 and CVE‑2023‑39780 exploits, turning them into a covert honeypot network that redirects traffic for adversary‑in‑the‑middle monitoring. The actors deploy the NetGhost shell script and reuse PolarEdge web shells to maintain persistence, evade detection by disabling logging, and redirect data through backdoors. Their activities target government, manufacturing, critical infrastructure, and energy sectors in CN, US, RU, PK, and TW, aiming at large‑scale observation and covert data interception.

Goals & Targeting

The actor’s primary objective appears to be building an expansive, low‑footprint honeypot network that can intercept and relay traffic for covert surveillance. By exploiting unpatched devices in critical infrastructure and governmental environments, ViciousTrap gains access to internal data streams while remaining obscured under legitimate device behaviors. The focus on financial-gain suggests the ultimate goal may include monetizing intercepted traffic or leveraging the collection of credentials from compromised networks for ancillary attacks.

Enhanced Description

Key Capabilities

  • Exploit CVE‑2023‑20118 in Cisco Small Business routers
  • Deploy malicious NetGhost shell script to redirect traffic
  • Enable adversary‑in‑the‑middle attacks via port forwarding
  • Implement self‑removal mechanism to reduce forensic evidence
  • Use FTPGET and wget for downloading additional scripts
  • Reuse undocumented PolarEdge web shells
  • Brute‑force login attempts
  • Exploit CVE‑2023‑39780 command injection on ASUS routers
  • Enable SSH access on custom TCP port 53282
  • Insert attacker‑controlled public key for remote access
  • Persist backdoor in non‑volatile memory that survives reboots and firmware updates
  • Disable router logging to evade detection

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 4 SHA-256 Hash 1 IPv4 Address 15

References

  1. www.cybersecuritydive.com — Cited by web research for: CVE-2023-39780
  2. www.techspot.com — Cited by web research for: Sift
  3. rewterz.com — Cited by web research for: PolarEdge
  4. thehackernews.com — Cited by web research for: WhatsApp
  5. gbhackers.com — Cited by web research for: PowerCat

Intel Summary

0

Techniques

42

Tools

0

Campaigns

21

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
EOL exploitation
Honeypot networks
Network monitoring

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.