3 ms·
The details on this are very vague. No one knows or is sharing the initial attack vector. It could be a browser spear phishing attack that then attempts to use
by joewee 8y ago
The details on this are very vague. No one knows or is sharing the initial attack vector. It could be a browser spear phishing attack that then attempts to use known default passwords for these routers and uploads a custom firmware image or backdoor script. The only thing that I don't get is why rebooting resolves the issue. This can't be accurate, if the compromise was via a user, its only a temporary resolution, and if the backdoor is as sophisticated as they say, it should definitely have persistence that last beyond reboot.
- eightysixfour 8y agoRebooting removes later stages, the first stage is persistent but one of the AV companies took down the domain that the later stages are retrieved from, effectively cutting it off from those stages.
- joewee 8y agoThanks for the clarification!
- rorosaurus 8y agoPer the last thread: https://news.ycombinator.com/item?id=17162245 https://news.ycombinator.com/item?id=17162245
- teilo 8y agoThis is a multi-vector, multi-architecture attack, and while we know some of the vectors, we don't know them all. Some were due to vulnerabilities in the router's web admin. Mikrotik routers were compromised in this way. In this case, it was not a default password issue (as their is no default password on Mikrotiks), but an attack that would work regardless of credentials. Anyone running firmware older than March 2018 who was not smart enough to block port 80 on their public interface likely got owned. Mikrotik is not a consumer router, but they are cheap and powerful, and thus attractive to end users, many of whom don't know what they are doing. Thankfully, the Mikrotiks are easily fixable. Upgrade the firmware, and stage 1 gets wiped out. But most consumer routers, by default, do not expose the web admin in this way, and were compromised by some other vector, and we have yet to get to the bottom of all of them. Many of these routers, due to their architecture, cannot be fixed with a firmware upgrade.