Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Chinese Hackers Mustang Panda Attacks TP-Link Routers
News & Analysis Attacks Internet of Things Security Malware Security Threats and Vulnerabilities

Chinese Hackers Mustang Panda Attacks TP-Link Routers

Olivia WilliamBy Olivia WilliamMay 16, 2023Updated:August 20, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Chinese Hackers Mustang Panda Attacks TP-Link Routers
Chinese Hackers Mustang Panda Attacks TP-Link Routers
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Chinese state-sponsored hacking outfit “Camaro Dragon” attacks household TP-Link routers with bespoke “Horse Shell” malware to attack European foreign affairs organizations. Hackers use backdoor virus in custom firmware for TP-Link routers to launch assaults from home networks.

According to Check Point research, this attack targets residential and home networks, not important networks. Thus, infecting a home router does not always suggest that the homeowner was a target, but rather that the attackers used it as a tool.

https://twitter.com/kyputer/status/1658581946165780481

The software lets threat actors run shell commands, upload and download data, and use the device as a SOCKS proxy to communicate between devices.

Check Point Research identified the Horse Shell TP-Link firmware intrusion in January 2023. The hackers’ behavior aligns with the Chinese “Mustang Panda” hacking outfit recently disclosed in Avast and ESET publications. Check Point calls this activity cluster “Camaro Dragon” despite its similarity to Mustang Panda.

The attackers’ server IP addresses, requests with hard-coded HTTP headers found on various Chinese websites, many typos in the binary code that indicate the author isn’t a native English speaker, and the trojan’s functional similarities to the APT31 “Pakdoor” router implant led to the attribution.

Check Point believes attackers infect TP-Link routers with the malicious firmware image by exploiting a vulnerability or brute-forcing administrator credentials. Threat actors can remotely upgrade the device with custom firmware after gaining admin access to the administrative interface.

Check Point identified two trojanized TP-Link router firmware images with considerable alterations and file additions. Check Point detected identical kernel and uBoot parts in the infected TP-Link firmware. The firmware used a modified SquashFS filesystem with Horse Shell backdoor malware components.

“We use Horse Shell to name the implant because parts of it are internally named.” Check Point says the implant offers remote shell, file transfer, and tunneling. When initialized, the Horse Shell backdoor implant tells the OS not to terminate its process when SIGPIPE, SIGINT, or SIGABRT commands are issued and to become a daemon.

The backdoor then sends the victim’s system profile to the command and control (C2) server, including the user name, OS version, time, device information, IP address, MAC address, and available implant capabilities.

The researchers say the Horse Shell firmware implant is firmware-agnostic and might function in firmware images for other routers from different vendors.

State-sponsored hackers commonly target poorly secured routers, which botnets use for DDoS attacks and crypto-mining. Routers are sometimes disregarded while establishing security measures and can serve as a stealthy launchpad for assaults, hiding the attacker’s origin.

Users should update their router firmware and change the default admin password. More importantly, restrict access to the device’s admin panel to the local network.

Chinese hackers implanted Fortinet VPN and SonicWall SMA routers with modified firmware. Recently, the UK NCSC and US CISA reported that Russian state-sponsored threat actors were also accessing Cisco routers to install proprietary malware.

Threat actors can exploit these devices without EDR (Endpoint notice and Response) security solutions to steal data, spread laterally, and launch more attacks without notice.

“There’s a recurring theme of continued China-nexus cyber espionage focus on network appliances, IOT devices, etc. that don’t support EDR solutions,” Mandiant CTO Charles Carmakal told BleepingComputer.

Network admins must apply all security patches on edge devices immediately and not publicly disclose management consoles.

Conclusion

Since January 2023, a new round of sophisticated and targeted attacks against European foreign affairs entities is suspected of having ties to the Chinese government actor Mustang Panda. According to Itay Cohen and Radoslaw Madej of Check Point, their investigation into these intrusions uncovered a unique firmware implant made for TP-Link routers. “The implant features several malicious components, including a custom backdoor named ‘Horse Shell,’ which allows the attackers to maintain persistent access, build anonymous infrastructure, and enable lateral movement into compromised networks,” the firm claimed. The implant’s components can be integrated into multiple suppliers’ firmware thanks to its “firmware-agnostic” design.

The Israeli cybersecurity company is keeping tabs on the attack organization called variously as Camaro Dragon, BASIN, Bronze President, Earth Preta, HoneyMyte, RedDelta, and Red Lich. It is presently unknown how the compromised firmware images were deployed to the infected routers or if they were used in any actual attacks. It’s possible that the initial entry was gained by exploiting a security hole or by brute-forcing devices using their factory settings or other simple passwords. The C++-based Horse Shell implant is known to allow attackers to perform arbitrary shell commands, transfer files to and from the router, and act as a communication relay for two clients. However, the router backdoor is speculated to attack random devices on private and residential networks, turning the compromised routers into a mesh network with the intention of establishing a “chain of nodes between main infections and real command-and-control.”

Olivia William
  • Olivia William
    Ciso Playbook: Cyber Resilience Strategy
  • Olivia William
    Apple Responds Swiftly to Active Security Threats with iOS 16.5.1 Update
  • Olivia William
    Zacks Investment Research Faces Larger Data Breach Affecting 8.8 Million Users
  • Olivia William
    British Airways and Boots Battling Data Breaches, Millions of Customers Affected

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}