ZuoRAT
- First seen
- 2022-06-22 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:23:04
Targeted industries: technology-and-telecommunications
Context
According to Black Lotus Labs, ZuoRAT is a MIPS file compiled for SOHO routers that can enumerate a host and internal LAN, capture packets being transmitted over the infected device and perform person-in-the-middle attacks (DNS and HTTPS hijacking based on predefined rules).
Reports & references
- Mandiant — Chinese Espionage Tactics (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Zuo Rat (report)
- blog.lumen.com — Zuorat Hijacks Soho Routers To Silently Stalk Networks (report)