ViciousTrap
- First seen
- 2022-05-01 00:00:00
- Primary motivation
- notoriety
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:23:49
Targeted industries: technology-and-telecommunications
Context
ViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots and utilizing a shell script called NetGhost to redirect incoming traffic from specific ports to their infrastructure. The actor has targeted various EOL devices, including ASUS routers, Linksys LRT224, and Araknis Networks AN-300-RT-4L2W VPN routers. Observations indicate attempts to deploy a web shell for executing their redirection script, although authorship of the web shell has not been attributed to ViciousTrap. The overall objectives of ViciousTrap remain unclear, but their activities suggest a honeypot-style network aimed at intercepting network flows.
Reports & references
- blog.sekoia.io — Vicioustrap Infiltrate Control Lure Turning Edge Devices Into Honeypots En Masse (report)