ViciousTrap is a threat actor that has compromised 5,500+ EOL devices using the NetGhost script to convert them into honeypots.
Analyst brief
ViciousTrap is a threat actor that has compromised over 5,500 edge devices, converting them into honeypots. It targets end-of-life (EOL) devices such as ASUS routers, Linksys LRT224, and Araknis Networks AN-300-RT-4L2W VPN routers. Key TTPs include using a shell script named NetGhost to redirect incoming traffic from specific ports to their infrastructure and attempting to deploy a web shell for script execution. Defenders should monitor EOL devices for abnormal port forwarding rules, indicators of the NetGhost script, and unauthorized web shell uploads.
ViciousTrap
unknown
ViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots and utilizing a shell script called NetGhost to redirect incoming traffic from specific ports to their infrastructure. The actor has targeted various EOL devices, including ASUS routers, Linksys LRT224, and Araknis Networks AN-300-RT-4L2W VPN routers. Observations indicate attempts to deploy a web shell for executing their redirection script, although authorship of the web shell has not been attributed to ViciousTrap. The overall objectives of ViciousTrap remain unclear, but their activities suggest a honeypot-style network aimed at intercepting network flows.