Sponsored Community Message Browse Free. Go deeper with Full Access. Free visitors can browse public knowledge. Full Access unlocks participation, member areas, and an ad-free experience.

FBI warns Russians hacked hundreds of thounited snakesnds of routers-gctid260649

Started by ?errthang, May 27, 2018, 12:29 PM

Previous topic - Next topic
 

FBI warns Russians hacked hundreds of thounited snakesnds of routers
 Reuters Fri, May 25 4:17 PM EDT?

FILE PHOTO: A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration
By Joseph Menn and Sarah N. Lynch

(Reuters) - The FBI warned on Friday that Russian computer hackers had compromised hundreds of thounited snakesnds of home and office routers and could collect user information or shut down network traffic.

The U.S. law enforcement agency urged the owners of many brands of routers to turn them off and on again and download updates from the manufacturer to protect themselves.

The warning followed a court order Wednesday that allowed the FBI to seize a website that the hackers planned to use to give instructions to the routers. Though that cut off malicious communications, it still left the routers infected, and Friday's warning was aimed at cleaning up those machines.

Infections were detected in more than 50 countries, though the primary target for further actions was probably Ukraine, the site of many recent infections and a longtime cyberwarfare battleground.

In obtaining the court order, the Justice Department said the hackers involved were in a group called Sofacy that answered to the Russian government.

Sofacy, also known as APT28 and Fancy Bear, has been blamed for many of the most dramatic Russian hacks, including that of the Democratic National Committee during the 2016 U.S. presidential campaign.

Earlier, Cisco Systems Inc said the hacking campaign targeted devices from Belkin International's Linksys, MikroTik, Netgear Inc, TP-Link and QNAP.

An FBI official told Reuters that the kinds of devices known to be affected by the hack were purchased by users at electronic stores or online.

However, the FBI was not ruling out the possibility that routers provided to customers by internet service companies could also be affected, the official added.

Cisco shared the technical details of its investigation with the U.S. and Ukrainian governments. Western experts say Russia has conducted a series of attacks against companies in Ukraine for more than a year amid armed hostilities between the two countries, causing hundreds of millions of dollars in damages and at least one electricity blackout.

The Kremlin on Thursday denied the Ukrainian government's accunited snakestion that Russia was planning a cyber attack on Ukrainian state bodies and private companies ahead of the Champions League soccer final in Kiev on Saturday.

"The size and scope of the infrastructure by VPNFilter malware is significant," the FBI said, adding that it is capable of rendering peoples' routers "inoperable."

It said the malware is hard to detect, due to encryption and other tactics.

The FBI urged people to reboot their devices to temporarily disrupt the malware and help identify infected devices.

People should also consider disabling remote-management settings, changing passwords and upgrading to the latest firmware.

(Reporting by Sarah N. Lynch in Washington and Joseph Menn in San Francisco; Editing by David Gregorio)

 

 

https://hothardware.com/news/vpnfilter-router-malware-wreaking-havoc-worldwide-infecting-new-devices

 
VPNFilter Router Malware Still Wreaking Havoc Worldwide Infecting New Devices

     ?

image: https://hothardware.com/ContentImages/NewsItem/44732/content/switch.jpg


Cisco, the world's largest networking company in the world, has published additional details in regards to VPNFilter, a nasty piece of malware that was discovered to have infected half a million consumer network devices scattered across 54 countries last month. The company's latest findings indicate that VPNFilter is targeting even vendors, including ASUSD-LinkHuawei, Ubiuiti, UPVEEL, and ZTEL. It's also attacked new devices from previously affected vendors, including Linksys, MikroTik, Netgear, and TP-Link.

 

"In the days since we first published our findings on the campaign, we have seen that VPNFilter is targeting more makes/models of devices than initially thought, and has additional capabilities, including the ability to deliver exploits to endpoints. Talos recently published a blog about a broad campaign that delivered VPNFilter to small home-office network devices, as well as network-attached storage devices. As we stated in that post, our research into this threat was, and is, ongoing," Cisco said.

?

image: https://hothardware.com/ContentImages/NewsItem/44732/content/FBI_Botnet-Exploit-Example-Cisco.jpg

VPNFilter (Source: Cisco)

 

The networking firm also discovered a new state 3 module that injects malicious code into web traffic as it passes through a network device. Leveraging the newly discovered module, a malicious actor could deliver exploits to endpoints through what's called a man-in-the-middle attack, which entails intercepting network traffic before it reaches the destination and infecting it with dirty code.

 

"With this new finding, we can confirm that the threat goes beyond what the actor could do on the network device itself, and extends the threat into the networks that a compromised network device supports," Cisco added.

 

All of this is aimed at creating a massive botnet that uses several stages of malware to infiltrate routes and network attached storage (NAS) devices. In the aftermath of the original discovery, the Justice Department and Federal Bureau of Investigation advised the public to reboot their routers and NAS boxes, and to check for any firmware updates.

 

Presumably that advice still stands. However, Cisco notes that the threat from VPNFilter continues to grow and has expanded in scope beyond the devices themselves, and into the networks those affected devices support. Cisco's own devices are not affected, fortunately.

Read more at https://hothardware.com/news/vpnfilter-router-malware-wreaking-havoc-worldwide-infecting-new-devices#0ywtPjfsZ8yuv2jp.99