Also known as: tracked as, CVE-2023-39780, to execute system commands, CVE-2023-20118, Sift
ViciousTrap emerged as a sophisticated threat actor that leveraged newly discovered vulnerabilities – CVE‑2023‑20118 in Cisco Small Business routers and CVE‑2023‑39780 in ASUS router firmware – to gain privileged access on hundreds of thousands of IoT and edge devices worldwide. Once compromised, the attackers deploy the lightweight NetGhost shell script to manipulate port forwarding rules, effectively turning each device into a man‑in‑the‑middle proxy that can intercept traffic destined for legitimate destinations. The cohort shares and re‑uses tooling with other botnets such as PolarEdge, evidencing an ecosystem of off‑the‑shelf components. Persistence is achieved by writing backdoors to non‑volatile memory, injecting attacker public keys into the SSH configuration under custom ports (e.g., TCP/53282), and disabling native logging features so that forensic footprints are minimized. The botnet’s scale – over 5,500 compromised devices – enables a broad surveillance network with high covertness. Operationally, ViciousTrap focuses on sectors where prolonged, low‑profiling observation can yield strategic intelligence, while the use of diverse vendor devices dilutes attribution and complicates incident response. Its attacks begin via brute‑force credential attempts followed by exploitation of command‑injection vulnerabilities, creating a funnel that turns unmanaged routers into stealthy reconnaissance assets.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ViciousTrap has compromised thousands of edge routers across more than 80 countries using the zero‑day CVE‑2023‑20118 and CVE‑2023‑39780 exploits, turning them into a covert honeypot network that redirects traffic for adversary‑in‑the‑middle monitoring. The actors deploy the NetGhost shell script and reuse PolarEdge web shells to maintain persistence, evade detection by disabling logging, and redirect data through backdoors. Their activities target government, manufacturing, critical infrastructure, and energy sectors in CN, US, RU, PK, and TW, aiming at large‑scale observation and covert data interception.
Goals & Targeting
The actor’s primary objective appears to be building an expansive, low‑footprint honeypot network that can intercept and relay traffic for covert surveillance. By exploiting unpatched devices in critical infrastructure and governmental environments, ViciousTrap gains access to internal data streams while remaining obscured under legitimate device behaviors. The focus on financial-gain suggests the ultimate goal may include monetizing intercepted traffic or leveraging the collection of credentials from compromised networks for ancillary attacks.
Enhanced Description
Key Capabilities
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
42
Tools
0
Campaigns
21
IOCs
0
Observed Data
0
Tactics