Bulbature, beneath the waves of GobRAT
Sekoia TDR published a comprehensive analysis of a Chinese-attributed infrastructure controlling 63+ servers that compromise edge devices (primarily Asus/Qnap routers) and transform them into Operational Relay Boxes (ORBs). The campaign deploys two malwares—GobRAT (a Go-based RAT with DDoS/exploitation capabilities) and Bulbature (an undocumented C-based implant providing proxy tunneling)—to relay offensive attacks and enable rotating proxy infrastructure. A July 2023 export revealed ~75,000 compromised relay boxes, predominantly US-based, with active infrastructure still operating as of September 2024.