Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/11/2018
05:20 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Attackers Using New Exploit Kit to Hijack Home & Small Office Routers

Goal is to steal banking credentials by redirecting users to phishing sites.

Small and home office routers are becoming major targets for criminals seeking to steal banking and other online account credentials belonging to Internet users.

The latest indication of the trend is "Novidade," a dangerous new exploit kit that multiple attack groups appear to be using to target routers belonging to millions of users in Brazil and, to a lesser extent, other parts of the world.

The malware is being used to change Domain Name Service (DNS) settings on routers so all traffic through them is hijacked and routed to a malicious server. When users of Novidade-infected routers attempt to access certain target banks, for instance, their traffic is redirected to cloned versions of the login pages of the bank they are trying to access.

Security vendor Trend Micro has been tracking the threat for some time and estimates that one attack campaign alone has delivered Novidade at least 24 million times since March. Telemetry that the company has obtained suggests that attacks involving the malware may have begun in August 2017.

Most of the attacks have involved attempts to retrieve banking credentials from Internet users in Brazil. But some of the Novidade campaigns have involved targets in no specific geographic location, suggesting either that the attackers are expanding their efforts or that a large group of actors are using the kit, Trend Micro said in a report this week.

Attackers appear to have managed to compromise multiple router models using Novidade, Trend Micro said. Examples include D-Link's DSL-2740R and DIR 905L, Mediabridge's Medialink MWN-WAPR300, Motorola's SBG6580, and TP-Link's TL-WR340G and WR1043ND router models.

"The Novidade exploit kit is another proof point showing that attackers are shifting targets when attacking consumers," says Mark Nunnikhoven, Trend Micro's VP of cloud research. "This malware uses a foothold — your laptop or desktop — to attack the heart of the home network: your router."

By changing a router's DNS settings, attackers can attempt to compromise other devices or phishing credentials at the leisure, Nunnikhoven says.

Novidade is the second major instance in recent months of cybercriminals using malware to change DNS settings on small office and home office (SOHO) routers in order to steal user credentials and conduct other malicious activities.

In August, security vendor Radware reported DNS hijacking attempts targeting Brazilian users of D-Link DSL modems. By October, the campaign had exploded in scope to target users of nearly six-dozen router models in Brazil and elsewhere. China's Qihoo 360's Netlab team, which was the first to report on the increased scope, estimated that as many as 100,000 routers belonging mostly to users in Brazil had been compromised with versions of DNSChanger, a previously known router hijacking tool.

Earlier this year, the FBI warned of foreign cyber actors targeting SOHO routers with VPNFilter, a particularly pernicious malware tool capable of persisting through reboots and rendering infected routers unusable. VPNFilter is believed to have infected some 500,000 SOHO routers worldwide.

Trend Micro described attackers using a variety of methods to distribute Novidade. This includes malvertising, website injections, and instant messages using the 2018 Brazilian presidential elections as a lure. "Once the victim receives and clicks the link to Novidade, the landing page will initially perform several HTTP requests generated by JavaScript Image function to a predefined list of local IP address that are mostly used by routers," the vendor said.

If a connection is successfully established, Novidade then "blindly" attacks the IP address with all its exploits. Next, it tries to log in to the router using default account names and passwords, after which it executes an attack to change the router's DNS settings.

Trend Micro says it has observed a least three variants of Novidade being used in the various attack campaigns. All three variants are delivered the same way and attack routers in the same manner. However, the newer variants have capabilities that the initial variant released in August 2017 did not have.

"The second version of Novidade added obfuscation to the JavaScript component, making it more difficult to detect," Nunnikhoven says. "The third version, continue to refine that obfuscation technique and added the ability to detect the local IP address, setting up the possibility of highly targeted attacks."

The best way for users to mitigate their exposure to threats like Novidade is to ensure their routers have the latest firmware version and are properly patched. Users should also change default usernames and passwords, change the router's default IP address, and disable remote access features so an external actor cannot manipulate it, according to Trend Micro.

Malware like Novidade presents a threat mostly to consumers. In theory, the same conceptual attack could work against enterprises, Nunnikhoven notes. "[But] it's significantly more difficult given the separation of duties and layers of security controls around key assets like Dynamic Host Configuration Protocol (DHCP) servers and enterprise DNS resolution," he says.

Related Content:

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
Robert Lemos, Contributing Writer,  2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9351
PUBLISHED: 2020-02-23
An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML data in the _transaction parameter, the server replies with a verbose error showing where the application resides (the a...
CVE-2020-9352
PUBLISHED: 2020-02-23
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter.
CVE-2020-9353
PUBLISHED: 2020-02-23
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL is affected by unauthenticated Local File Inclusion via directory-traversal sequences in the elem XML ...
CVE-2020-9354
PUBLISHED: 2020-02-23
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an XML comment and /.. pat...
CVE-2020-9355
PUBLISHED: 2020-02-23
danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.