Backdoor Targets Linux-Based iKuai Routers

· Original article ↗

Summary

A technical analysis details an ELF backdoor that appears to target iKuai routers, beaconing to a command-and-control server and supporting shell commands, file exfiltration, and payload execution.

Key points

  • The ELF impersonates OpenWrt’s libjson_script.so and checks iKuai-specific identifiers in /etc/release.
  • It collects device details, encrypts them with AES-256, and communicates with a C2 server over HTTPS without certificate validation.
  • C2 commands can execute shell commands, download and run payloads, schedule tasks, change directories, and exfiltrate files up to 512 KB.
  • The sample uses XOR with key 0x5A to decrypt configuration strings and defaults to beaconing every hour.
  • The analyzed sample’s SHA-256 is 4e6276cc400b3b9e9616d04474b64a8fa0c35375b9673ab41a92a6d5bce72d8d; the reported C2 is 47.80.111[.]129:7380.
  • The researcher found no additional samples using a YARA rule and described the backdoor as apparently rare.

Article Details

Attack Vectors
  • An ELF backdoor impersonates the legitimate libjson_script.so library and appears to target Linux-based iKuai routers.
  • The backdoor beacons to a C2 server for commands, including commands to download and execute payloads, run shell commands, and read and exfiltrate files.
Defensive Notes
  • The researcher provided a deliberately broad Yara rule matching command strings, C2 paths, and device-profiling strings in ELF files under 10 MB.
  • The researcher reported finding no additional samples with that rule.

Indicators of compromise

TypeIndicatorContext
SHA2564e6276cc400b3b9e9616d04474b64a8fa0c35375b9673ab41a92a6d5bce72d8dSHA-256 hash of the ELF backdoor named libjson_script.so.0.
URLhxxps[:]//47[.]80[.]111[.]129:7380C2 address embedded in the backdoor configuration and listed as an IOC.
URLhxxps[:]//47[.]80[.]111[.]129:7380/cdn-cgi/bm/cv/resultC2 endpoint receiving encrypted command results.
URLhxxps[:]//47[.]80[.]111[.]129:7380/cdn-cgi/challenge-platform/generate/ov1C2 endpoint used by the __uu__ command to download a payload.
URLhxxps[:]//47[.]80[.]111[.]129:7380/cdn-cgi/traceC2 endpoint receiving encrypted device-profiling information.

MITRE ATT&CK

Vendors

Products

Related Articles