Chinese hacking group APT31 uses mesh of home routers to disguise attacks

OVERKILL

$100 Site Donor 2021
Joined
Apr 28, 2008
Messages
61,194
Location
Ontario, Canada
https://therecord.media/chinese-hacking-group-apt31-uses-mesh-of-home-routers-to-disguise-attacks

This is an older (2021) article, but it quotes Ben Koehl, who works at Microsoft's Threat Intelligence Center, indicating that using these bots as proxies makes the attack appear to be coming from domestic IP's to circumvent geoblocking.

I got into this in the couple of other threads and this utilization is in-line with the TP-Link Camaro Dragon thread where Chinese operatives are hijacking Chinese-origin products (TP-Link products) in order to wage cyber attacks.

There is plenty of utility here, a few that immediately come to mind are:
1. You hide the malicious traffic behind an endpoint that's compromised and isn't having its traffic monitored because it's a consumer device and connection
2. You circumvent geoblocking by having the traffic originate inside domestic borders
3. You can use a host of different devices to vary the location of the attack and even proxy through multiple devices if you really wanted to obfuscate the origin


Most home network gear is akin to a house owned by Ray Charles with noise cancelling headphones on. He's got no idea what's going on, who is coming in and out, hell, he could have a terrorist cell operating out of one of his bedrooms and he'd have no idea. With the Chinese-sourced devices like TP-Link, the idea that the terrorists might already have keys for 'ol Ray's house isn't far fetched.
 
Ack, I recently installed a TP-Link Wi-fi range extender. Does this put me at risk of being hacked?
With it not being directly exposed to the internet, it's far less likely than with a TP-Link edge device, which are what were being compromised in the Camaro Dragon thread. That said, it could have crap software like their lightbulbs.
 
Can't add valuable content to this thread, but I am in the market for a new router. Any suggestions for the best, safest, or??
 
Well this certainly is above my pay grade, but I think its time I stepped up. One won't get it; I presume it will feed a switch as I need two ethernet feeds. Looking at the web site, it makes my head spin. I don't have much in the way of technical needs, only a mesh unit to cover the rest of my house. Which one of the APs would be good for that?
Appreciate your advice.
 
Well this certainly is above my pay grade, but I think its time I stepped up. One won't get it; I presume it will feed a switch as I need two ethernet feeds. Looking at the web site, it makes my head spin. I don't have much in the way of technical needs, only a mesh unit to cover the rest of my house. Which one of the APs would be good for that?
Appreciate your advice.
How big is the house? Their cheapest AP is probably fine to extend the coverage.
 
Ubiquiti makes good product. However they are likely overkill for most residential consumer grade customers.

Bots likely will be on most consumer grade stuff as the developers will try to target them. If I'm one of them I'd definitely aim for Netgear Linksys DLink Asus as well (Chinese is definitely not the only one thinking about it).
 
Back
Top Bottom