May 29, 2023, 4:31 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

JPCERT/CC has confirmed attacks that infected routers in Japan with malware around February 2023. This blog article explains the details of the attack confirmed by JPCERT/CC and GobRAT malware, which was used in the attack.


Attack flow up to malware execution


Initially, the attacker targets a router whose WEBUI is open to the public, executes scripts possibly by using vulnerabilities, and finally infects the GobRAT. Figure 1 shows the flow of the attack until GobRAT infects the router.



Figure 1: …

article attack attacks blog february flow japan language linux malware malware analysis router routers targeting webui

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior Cloud Security Engineer

@ Hearst | Charlotte, NC, United States

Junior Cybersecurity Analyst

@ SavageOne | Johannesburg, GP, South Africa

Information Security Risk Analyst

@ Take-Two Interactive Software, Inc. | Bengaluru, Karnataka, India