Categories: NewsSecurity

xLED Malware Lets Criminals Exfiltrate Sensitive Information Through Router LEDs

Internet criminals have come up with yet another creative way to steal data from secure corporate networks. This new method revolves around infecting routers and switches with a new type of malware. As a result of such an infection, the malicious software can control the device’s LEDs and use them to transmit information in the binary format. This does require the attacker to be nearby, though, but it is still a troublesome development.

Led-controlling Malware Is Becoming a Problem

It is quite problematic to think of malware which transmits data by controlling the LEDs fading on a modem or network switch. Since these devices constantly display LEDs – which often flicker if traffic is routed through the device – it is quite difficult to determine when something malicious is going on. Moreover, the assailant needs to be close to the infected device to capture this information, which can be done by using off-the-shelf video recording equipment.

It is evident not too many criminals will use this method of attack anytime soon. However, company employees who hold a grudge against the enterprise they work for could certainly use this malware to their advantage. That is, assuming they get their hands on a working sample. For now, this attack vector is merely a proof of concept developed by researchers in Israel. However,  it shows data can be extracted from networks by manipulating LEDs on these devices.

The malware developed for this particular purpose goes by the name of xLED. The malicious software is capable of intercepting particular data passing through a router or network switch. This information is then converted into a binary data stream and rebroadcasted using the LEDs found on the front of said router or switch. It sounds like a complicated way of broadcasting sensitive data, but it is also an inconspicuous method of doing so. Anyone with a clear line of sight can record the LEDs flashing and exfiltrate data from doing so.

Related Post

As is somewhat to be expected, more LEDs on the router or switch will result in more information being transmitted. Various configurations of these devices have been tested, and it turns out data can be exfiltrated at a rate of up to 1000 bits/second per LED. Multiple LEDs will exponentially increase the amount of information broadcasted. Most enterprise-grade routers and switches have at least seven LEDs these days.

One thing to take into account is how assailants will still need to install this malware on the router or switch. That is not all that difficult, as criminals have been quite successful in doing so for quite some time now. It does not appear xLED or any other similar versions of this malware require physical access to the router or switch to be installed. This means a regular malware distribution campaign can be quite useful to infect routers and switches with this type of malware.

Although this is a relatively new threat, it is not the most convenient way to exfiltrate sensitive information from companies by any means. It is a very impractical way of going about things, to say the least. That does not mean criminals will be dissuaded from giving it a try, though, assuming they can gain access to internal security cameras to record the stream of binary information transmitted by the LEDs. Rest assured this type of malware may make the rounds in the coming years, though, as it is an inconspicuous way of stealing sensitive information.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx
Tags: malwarexLED

Recent Posts

Bitcoin Crashes Below $67,000 as $700 Million Wiped From Crypto Market in Hours

Bitcoin is bleeding. The world's largest cryptocurrency plunged to $66,997 on Tuesday, shedding over $6,750…

3 hours ago

Ripple’s RLUSD Goes Live in Türkiye, Hits $1.7 Billion Market Cap

Ripple is not pausing for breath. The company has brought its dollar-pegged stablecoin, $RLUSD, to…

7 hours ago

Bitwise Launches Its First Tokenized Fund With $259M in Assets and 4% Annual Yield

Bitwise Asset Management has just made its first move into tokenized funds, and it comes…

1 day ago

Binance Launches US Stocks and ETFs Trading for Non-US Users With Zero Commission

Binance just made a move that blurs the line between crypto exchange and traditional brokerage…

1 day ago

NEAR Protocol Ships Confidential Payments, Crosses $19B in Intents Volume, and Partners With Bermuda Government

NEAR Protocol has had a month that most blockchain projects would stretch across an entire…

2 days ago

Chainlink Records 7 New Integrations Across 6 Services and 4 Chains

Something is becoming increasingly clear about Chainlink, the integrations are not slowing down. The protocol…

2 days ago