Cuttlefish Malware
Summary
This particular malware is built in a modular fashion, primarily targeting the theft of authentication information from Web requests passing through the router on the Local Area Network (LAN). Additionally, it possesses the capability to perform DNS and HTTP hijacking for connections within private IP space, typically associated with internal network communications. There are indications from the source code that suggest similarities with a previously identified activity cluster known as HiatusRAT, though no instances of shared victimology have been observed thus far. However, once a foothold is established, a bash script is deployed to collect host data, including/etc., contents, running processes, active connections, and mounts. Moreover, the malware can act as a proxy or VPN, allowing captured data to be transmitted through the compromised router and facilitating threat actors in using collected credentials to access targeted resources.