Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The worm will connect first to port 8080, and if necessary using SSL, to request the "/HNAP1/" URL. This will return an XML formatted list of router features and firmware versions. The worm appears to extract the router hardware version and the firmware revision. | Once this code runs, the infected router appears to scan for other victims. The worm includes a list of about 670 different networks... Indicators of compromisse: - heavy outbound scanning on port 80 and 8080.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A self-replicating worm that targeted Linksys routers by exploiting authentication bypass flaws.
A self-propagating ELF MIPS worm targeting vulnerable Linksys routers via an unauthenticated exploit against a CGI script exposed through HNAP-related probing. It fingerprints router model and firmware, downloads and executes a roughly 2MB payload, scans ISP-linked networks for additional victims, and briefly hosts its binary on random low ports for lateral propagation. The sample also contains strings suggesting a possible command-and-control capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.