ZuoRAT

Malware

⚠️ Overview

ZuoRAT is a multi-stage remote access trojan (RAT) first publicly documented in June 2022 by Lumen Technologies’ Black Lotus Labs, targeting small office/home office (SOHO) routers—specifically MikroTik devices—for espionage operations attributed to a Chinese state-sponsored threat actor tracked as UNC3524 (Mandiant) or APT31. The malware belongs to the RAT category and is part of a sophisticated supply-chain attack vector that leverages compromised routers as stealthy C2 infrastructure.

🔧 Technical Capabilities

ZuoRAT employs a multi-stage architecture: an initial loader (stage 1) is delivered via brute-force attacks or vulnerability exploitation (e.g., CVE-2018-14847 on MikroTik RouterOS), followed by a downloader (stage 2) that fetches the core payload (stage 3) from hardcoded IPs or domains. The core RAT uses encrypted communications over TCP/443 with custom User-Agent strings mimicking legitimate browsers, and it implements persistence by modifying the router’s firmware or injecting into the routerboard file system. Evasion techniques include traffic mimicking, payload obfuscation with XOR and Base64, and dynamic DNS for C2 rotation. The malware can perform network reconnaissance, proxy traffic for lateral movement, and exfiltrate sensitive data such as VPN credentials and internal network topology. It also supports file upload/download, shell command execution, and port forwarding.

📜 History & Notable Incidents

First identified in mid-2021 during an investigation of a telecom breach, ZuoRAT’s major campaign targeted US and European government agencies, defense contractors, and telecommunications firms, with evidence of prolonged access (up to 18 months) before discovery. The campaign exploited older RouterOS vulnerabilities (CVE-2018-14847, CVE-2022-33173) and leveraged compromised MikroTik devices as hidden C2 proxies to obfuscate the attacker’s origin. No public law enforcement takedowns have been reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 3c3a3e6c1b1b0f5a0d4e7f8c2a9b1c0d (stage 1 loader) and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (core payload); behavioral signatures include unexpected RouterOS file modifications under /flash/rw and anomalous outbound connections on TCP/443 with User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (specifically with a trailing space). Network IOCs include domains ending in .ddns.net and IPs belonging to cloud hosting providers like DigitalOcean. Registry keys are not applicable due to the router-based environment.

☠️ Risk & Impact

ZuoRAT enables long-term espionage by exfiltrating VPN credentials, network diagrams, and sensitive internal data, leading to potential intellectual property theft and operational security compromises. The primary affected sectors are government, defense, and telecommunications in North America and Europe, with financial losses estimated in the millions due to incident response and remediation costs. The use of compromised routers as C2 bridges also facilitates lateral movement into high-value internal networks.

🛡️ Mitigation

Defensive measures include immediately patching MikroTik RouterOS to the latest version (especially for CVEs CVE-2018-14847 and CVE-2022-33173), implementing strong unique passwords, disabling unused services, and monitoring for anomalous DNS queries or unexpected firmware changes. Network detection rules (e.g., Snort or Zeek signatures) can flag the specific User-Agent strings and outbound connections to known dynamic DNS domains, while router firmware integrity checks using RouterOS’s built-in check-firmware command help identify tampering. For further details, refer to Black Lotus Labs’ report at https://blog.lumen.com/zuorat-malware-router-espionage/ and MITRE ATT&CK technique T1485 for data destruction.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.