From HiatusRAT to Cuttlefish: advances in credential theft through the router

Danny Adamitis

BSides NYC 2024 · Day 1 · Tech - Red

In a revealing presentation at BSides NYC, Danny Adamitis, a researcher from Lumen Technologies' Black Lotus Labs, unveiled a detailed case study of persistent and sophisticated Chinese espionage campaigns known as **HiatusRAT** and **Cuttlefish**. This talk illuminated how advanced persistent threat (APT) groups are shifting their focus from traditional endpoints, which are increasingly well-defended, to overlooked network infrastructure like routers and cloud services. The research, which spans from 2021 and continues to the present day, demonstrates an alarming level of brazenness and resilience from the adversaries, who often ignore public disclosures and continue operations with minimal changes.

AI review

Adamitis brings original, longitudinal threat intelligence on two real campaigns with technical receipts — build paths, certificate patterns, live C2 confirmation on the day of the talk. This is practitioner-grade research that advances the router-as-target conversation with specificity rather than hand-waving.

Watch on YouTube