The Federal Bureau of Investigation (FBI) issued an important Private Industry Notification (PIN), warning organizations about an emerging malware campaign using HiatusRAT as part of an elaborate global malware campaign targeting Chinese-brand web cameras and digital video recorders (DVRs) from different nations across multiple regions.
HiatusRAT has rapidly progressed into an extremely potent cyber threat since July 2022, breaching various network devices including those belonging to US government servers and Taiwanese organizations. Their latest campaign launched in March 2024 has expanded their target reach into multiple jurisdictions such as the US, Canada, UK Australia & New Zealand.
Technical Exploitation Methods
Cybercriminals have multiple attack vectors at their disposal to breach network devices, with particular attention paid to:
- Hikvision cameras
- D-Link devices
- Xiongmai technology products
The hackers exploit multiple unpatched security vulnerabilities, including:
- CVE-2017-7921
- CVE-2020-25078
- CVE-2018-9995
- CVE-2021-33044
- CVE-2021-36260
Advanced Scanning and Brute-Force Techniques
The attackers employ sophisticated tools to breach device security:
- Ingram: A GitHub-based webcam scanning tool
- Medusa: An open-source brute-force authentication cracking tool
They target specific TCP ports, including 23, 26, 554, 2323, 567, 5523, 8080, 9530, and 56575, demonstrating a comprehensive approach to network infiltration.
Recommended Mitigation Strategies
The FBI provides comprehensive guidance for organizations to protect against HiatusRAT:
- Isolate vulnerable devices from networks
- Implement multi-factor authentication
- Enforce strong password policies
- Regularly update firmware and software
- Monitor network activities consistently
- Review and update security policies
Cybersecurity experts, including Sonu Shankar, a former federal critical infrastructure official, are actively collaborating with Chief Information Security Officers (CISOs) to address the escalating threat these malware campaigns pose.




