ViciousTrap is a threat actor active since at least March 2025 that compromises internet-facing edge devices and repurposes them into a distributed honeypot-like interception network. The actor has been observed exploiting CVE-2023-20118 in Cisco small-business routers and also targeting other edge-device classes and brands, including ASUS, D-Link, Linksys, QNAP, SSL VPN appliances, DVRs, NAS devices, and BMC controllers. Reporting associates the campaign with more than 5,000 compromised devices across dozens of countries. The actor’s tradecraft centers on converting compromised devices into traffic-redirection nodes. After initial exploitation, ViciousTrap deploys shell-scripted payloads including NetGhost, which modifies NAT and port-forwarding behavior to redirect inbound traffic on common web-management ports to attacker-controlled infrastructure. This enables adversary-in-the-middle interception, monitoring of exploitation attempts, and likely collection or reuse of tooling and access from other actors. The infection chain has also used a dropped BusyBox wget binary, staged payload delivery, self-deleting scripts to reduce forensic artifacts, and selective payload serving to confirmed victims. ViciousTrap has also been linked to exploitation of ASUS routers in activity involving establishment of SSH access on a nonstandard port, and some researchers assess overlap between this activity and the AyySSHush botnet. The broader operation has been described as resembling an operational relay box network built from compromised routers and embedded devices. The actor has reused a previously documented PolarEdge-related webshell, although authorship of that tooling is unconfirmed and may reflect collection or repurposing rather than original development. Attribution remains unconfirmed, but multiple assessments describe ViciousTrap as likely Chinese-speaking based on limited infrastructure overlap with GobRAT and the geographic distribution of monitored and targeted assets. The actor’s apparent objective is intelligence collection and infrastructure building rather than overt disruption or extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
ViciousTrap initiates compromise by leveraging the Cisco SOHO router vulnerability, tracked as CVE-2023-20118, which enables command and bash script execution.
Exploit CVE-2023-39780, an authenticated command injection vulnerability, through a malicious OAuth Google refresh token parameter... Since the SSH key is added via the router’s official config interface, it is retained across firmware updates, meaning they can maintain access even after CVE-2023-39780 is patched.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised thousands of network edge devices globally by exploiting Cisco Small Business router CVE-2023-20118, building a honeypot-like network.
Named as a possibly connected threat actor due to shared C2 infrastructure with the AyySSHush ASUS router botnet campaign, but attribution remains unclear.
A campaign tracked by Sekoia targeting SOHO routers, as well as more than 50 manufacturers' devices, SSL VPNs, DVRs, and BMC controllers, turning them into honeypots.
Compromised thousands of edge devices (SOHO routers, SSL VPNs, DVRs, BMC controllers) and repurposed them at scale as distributed honeypots/monitoring nodes—likely to observe exploitation attempts, collect exploit tradecraft (potentially including non-public/0-day), and possibly reuse access obtained by other threat actors (also consistent with ORB-style infrastructure).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.