AVrecon
- First seen
- 2023-07-01 00:00:00
- Malware type
- rat, downloader
- Family
- Malware family
- Last IoC activity
- 2026-07-21 15:58:40
- Profile updated
- 2026-07-07 14:21:49
Targeted industries: technology-and-telecommunications retail-and-hospitality media-and-entertainment
Context
AVrecon is a Linux-based Remote Access Trojan (RAT) targeting small-office/home-office (SOHO) routers and other ARM-embedded devices. The malware is distributed via exploitation of unpatched vulnerabilities or common misconfiguration of the targeted devices. Once deployed, AVreckon will collect some information about the infected device, open a session to pre-configured C&C server, and spawn a remote shell for command execution. It might also download additional arbitrary files and run them. The malware has recently been used in campaigns aimed at ad-fraud activities, password spraying and data exfiltration.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Avrecon_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Avrecon (report)
- spur.us — Christmas In July A Finely Wrapped Proxy Service (report)
- krebsonsecurity.com — Who And What Is Behind The Malware Proxy Service Socksescort (report)
- blog.lumen.com — Routers From The Underground Exposing Avrecon (report)
- twitter.com — 1684290046235484160 (report)