AVrecon

First seen
2023-07-01 00:00:00
Malware type
rat, downloader
Family
Malware family
Last IoC activity
2026-07-21 15:58:40
Profile updated
2026-07-07 14:21:49

Targeted industries: technology-and-telecommunications retail-and-hospitality media-and-entertainment

Context

AVrecon is a Linux-based Remote Access Trojan (RAT) targeting small-office/home-office (SOHO) routers and other ARM-embedded devices. The malware is distributed via exploitation of unpatched vulnerabilities or common misconfiguration of the targeted devices. Once deployed, AVreckon will collect some information about the infected device, open a session to pre-configured C&C server, and spawn a remote shell for command execution. It might also download additional arbitrary files and run them. The malware has recently been used in campaigns aimed at ad-fraud activities, password spraying and data exfiltration.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Avrecon_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Avrecon (report)
  • spur.us — Christmas In July A Finely Wrapped Proxy Service (report)
  • krebsonsecurity.com — Who And What Is Behind The Malware Proxy Service Socksescort (report)
  • blog.lumen.com — Routers From The Underground Exposing Avrecon (report)
  • twitter.com — 1684290046235484160 (report)

External references