Attacks/Breaches

8/2/2018
06:30 PM
50%
50%

Cryptojacker Campaign Hits MikroTik Routers

More than 200,000 routers hit with a sophisticated cryptomining attack that appears to be spreading.

In March, routers from Latvian manufacturer MikroTik were hit by an advanced threat dubbed Operation Slingshot. The company patched for the threat, but now a new cryptomining attack has hit MikroTik routers and appears to be spreading rapidly.

The original Operation Slingshot campaign was spyware that was able to gather screenshots, keyboard data, network data, passwords, various desktop activity, the clipboard, and more without ever using a zero-day exploit. Instead, the attack took advantage of two modules that were able to implant themselves in a targeted router. Those modules were accompanied by very sophisticated detection evasion techniques that included shutting down the attack if certain forensic activities were detected. Nevertheless, the attack was discovered and countered.

This time around, researchers have found a new MikroTik-targeting cryptojacking campaign that began with routers in Brazil and is now spreading beyond those borders. The campaign, which injects cryptomining software into traffic transiting an infected MikroTik router, was so successful that the performance hit was what drew attention to the attack; the threat actor then shifted strategies to only inject the miner through router-based error pages.

According to researchers at Trustwave, the attack has now hit more than 200,000 routers, with the number still growing as of this writing. Further, tens of thousands of those routers are outside Brazil, indicating that any initial geographic targeting is no longer in effect.

"Everyone with a MikroTik router should be worried that they will be targeted no matter where they reside," says Karl Sigler, threat intelligence manager at Trustwave. Fortunately, those same global users have a meaningful response possible for the attack.

"Hopefully with enough coverage, users of MikroTik routers will patch their devices, Sigler adds. "A single patch [available since April] is enough to stop this exploitation in its tracks."

This is not the first time MikroTik owners have been urged to patch and reboot their routers. MikroTik equipment was specifically mentioned in the FBI's May 2018 call for router reboots, and even the March attack was effective only against routers that were not up to date with software patches.

Related Content:

 

 

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I guess this answers the question: who's watching the watchers?
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20029
PUBLISHED: 2018-12-10
The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read.
CVE-2018-1279
PUBLISHED: 2018-12-10
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on ...
CVE-2018-15800
PUBLISHED: 2018-12-10
Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.
CVE-2018-15805
PUBLISHED: 2018-12-10
Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files or cause a denial of service (resource consumption).
CVE-2018-16635
PUBLISHED: 2018-12-10
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.