ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

Emerging Cyber Threat Exploits Vulnerabilities in Web Cameras and DVRs

Christi by Christi
December 18, 2024
in Malware
Reading Time: 1 min read
FBI warns of HiatusRAT malware targeting web cameras and DVRs across US, Canada, UK, Australia. Critical security vulnerability affecting network devices worldwide.
Share on FacebookShare on Twitter

The Federal Bureau of Investigation (FBI) issued an important Private Industry Notification (PIN), warning organizations about an emerging malware campaign using HiatusRAT as part of an elaborate global malware campaign targeting Chinese-brand web cameras and digital video recorders (DVRs) from different nations across multiple regions.

HiatusRAT has rapidly progressed into an extremely potent cyber threat since July 2022, breaching various network devices including those belonging to US government servers and Taiwanese organizations. Their latest campaign launched in March 2024 has expanded their target reach into multiple jurisdictions such as the US, Canada, UK Australia & New Zealand.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Technical Exploitation Methods

Cybercriminals have multiple attack vectors at their disposal to breach network devices, with particular attention paid to:

  • Hikvision cameras
  • D-Link devices
  • Xiongmai technology products

The hackers exploit multiple unpatched security vulnerabilities, including:

  • CVE-2017-7921
  • CVE-2020-25078
  • CVE-2018-9995
  • CVE-2021-33044
  • CVE-2021-36260

Advanced Scanning and Brute-Force Techniques

The attackers employ sophisticated tools to breach device security:

  • Ingram: A GitHub-based webcam scanning tool
  • Medusa: An open-source brute-force authentication cracking tool

They target specific TCP ports, including 23, 26, 554, 2323, 567, 5523, 8080, 9530, and 56575, demonstrating a comprehensive approach to network infiltration.

Recommended Mitigation Strategies

The FBI provides comprehensive guidance for organizations to protect against HiatusRAT:

  1. Isolate vulnerable devices from networks
  2. Implement multi-factor authentication
  3. Enforce strong password policies
  4. Regularly update firmware and software
  5. Monitor network activities consistently
  6. Review and update security policies

Cybersecurity experts, including Sonu Shankar, a former federal critical infrastructure official, are actively collaborating with Chief Information Security Officers (CISOs) to address the escalating threat these malware campaigns pose.

Previous Post

Rhode Island Government Hacked – RIBridges System Shut Down After Potential Data Exposure

Next Post

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

Christi

Christi

Christi began her InfoSec carrier at the Illinois Institute of Technology where she received her Bachelor of Science degree in Applied Cybersecurity and Information Technology. Her passions include learning about new threats, data breaches, running, and playing with her dog, Pablo.

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Ransomware Attack Cripples PIH Health Whittier Hospital

December 6, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.