securityonline.info 6/1/2026, 10:18:52 AM · external

China linked hackers deploy Linux router implant to hijack DNS

China linked hackers deploy Linux router implant to hijack DNS
CyberSIXT Evidence Panel Source marked as original reporting

A cyber espionage campaign targeting enterprise operations in Southeast Asia has been identified, involving a China-linked group deploying a custom Linux router implant on border routing devices. This implant circumvents traditional security measures, allowing attackers access to internal web traffic. The malware operates as a static binary, using DNS over HTTPS for stealthy communication and manipulating firewall rules to hijack DNS traffic.

Additionally, it can gain access to internal Windows hosts through DLL sideloading, highlighting the need for enhanced security measures against such sophisticated threats.

View full article

Article by CyberSIXT