Backdoor Targets Linux-Based iKuai Routers

Summary
A technical analysis details an ELF backdoor that appears to target iKuai routers, beaconing to a command-and-control server and supporting shell commands, file exfiltration, and payload execution.
Key points
- The ELF impersonates OpenWrt’s libjson_script.so and checks iKuai-specific identifiers in /etc/release.
- It collects device details, encrypts them with AES-256, and communicates with a C2 server over HTTPS without certificate validation.
- C2 commands can execute shell commands, download and run payloads, schedule tasks, change directories, and exfiltrate files up to 512 KB.
- The sample uses XOR with key 0x5A to decrypt configuration strings and defaults to beaconing every hour.
- The analyzed sample’s SHA-256 is 4e6276cc400b3b9e9616d04474b64a8fa0c35375b9673ab41a92a6d5bce72d8d; the reported C2 is 47.80.111[.]129:7380.
- The researcher found no additional samples using a YARA rule and described the backdoor as apparently rare.
Article Details
- Attack Vectors
- An ELF backdoor impersonates the legitimate libjson_script.so library and appears to target Linux-based iKuai routers.
- The backdoor beacons to a C2 server for commands, including commands to download and execute payloads, run shell commands, and read and exfiltrate files.
- Defensive Notes
- The researcher provided a deliberately broad Yara rule matching command strings, C2 paths, and device-profiling strings in ELF files under 10 MB.
- The researcher reported finding no additional samples with that rule.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 4e6276cc400b3b9e9616d04474b64a8fa0c35375b9673ab41a92a6d5bce72d8d | SHA-256 hash of the ELF backdoor named libjson_script.so.0. |
| URL | hxxps[:]//47[.]80[.]111[.]129:7380 | C2 address embedded in the backdoor configuration and listed as an IOC. |
| URL | hxxps[:]//47[.]80[.]111[.]129:7380/cdn-cgi/bm/cv/result | C2 endpoint receiving encrypted command results. |
| URL | hxxps[:]//47[.]80[.]111[.]129:7380/cdn-cgi/challenge-platform/generate/ov1 | C2 endpoint used by the __uu__ command to download a payload. |
| URL | hxxps[:]//47[.]80[.]111[.]129:7380/cdn-cgi/trace | C2 endpoint receiving encrypted device-profiling information. |
MITRE ATT&CK
T1005 · Data from Local SystemThe __dd__ command reads files from the device for exfiltration.T1016 · System Network Configuration DiscoveryThe backdoor obtains the device's local IP address and includes IP address information in its C2 profile.T1027 · Obfuscated Files or InformationThe backdoor stores configuration strings encrypted with a single-byte XOR key and decrypts them at runtime.T1036.005 · Match Legitimate Resource Name or LocationThe ELF backdoor is named libjson_script.so.0 to impersonate the legitimate libjson_script.so library.T1041 · Exfiltration Over C2 ChannelThe __dd__ command sends file contents back to the C2, while command results are sent to a C2 reporting endpoint.T1059.004 · Unix ShellThe default C2 task action executes shell commands through /bin/sh -c.T1071.001 · Web ProtocolsThe backdoor uses HTTPS requests to beacon to its C2 and exchange tasks and results.T1082 · System Information DiscoveryThe backdoor collects device architecture, hostname, process ID, and version information for its C2 profile.T1105 · Ingress Tool TransferC2 commands direct the backdoor to download and execute additional payloads.T1573.001 · Symmetric CryptographyThe backdoor AES-encrypts device-profiling data and command results sent to the C2 and decrypts C2 responses.