ZuoRAT

First seen
2022-06-22 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 14:23:04

Targeted industries: technology-and-telecommunications

Context

According to Black Lotus Labs, ZuoRAT is a MIPS file compiled for SOHO routers that can enumerate a host and internal LAN, capture packets being transmitted over the infected device and perform person-in-the-middle attacks (DNS and HTTPS hijacking based on predefined rules).

Reports & references

  • Mandiant — Chinese Espionage Tactics (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Zuo Rat (report)
  • blog.lumen.com — Zuorat Hijacks Soho Routers To Silently Stalk Networks (report)

External references