Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Your Router Can Host Some Pretty Nasty Malware

Your Router Can Host Some Pretty Nasty Malware

Hundreds of millions of people use wireless Internet connections every day, and as a result, hackers are taking that as a challenge. They are now starting to develop malware that targets people through their routers. Recently, security researchers at Kaspersky Lab have discovered the malware named Slingshot. The code is designed to spy on PCs through a multi-layer attack that targets MikroTik routers. Today we take a look at Slingshot, and other router-based malware and what you can do about it.

Slingshot
Slingshot works by replacing a library file with a malicious version that downloads more malicious components and then eventually launches a two-front attack on the computers connected to it. The first one runs low-level kernel code that gives an intruder free rein of a system, while the other focuses on the user level and includes code to manage the file system and keep the malware alive.

It is a very intricate attack that calls the nefarious code in from an encrypted virtual file system; managing to do so without crashing the host system, a feat not lost on the security experts at Kaspersky Lab, who deemed it a state-sponsored attack because of the quality of the overall attack and the complexity of its components. Reports suggest that the malware can basically steal whatever it wants, including keyboard strokes, passwords, screenshots, and information about network usage and traffic.

MikroTik has announced that they have patched the vulnerability on versions of their routing firmware, but concerns remain as no one is sure if other router manufacturers have been affected. If that were to come to fruition, Slingshot could be a much larger problem than is currently believed.

Other Instances
Slingshot isn’t the first instance of a router turning on its owner. Traditionally, router security is known to be largely unreliable. Much of this is on the manufacturers, which have been known to build many different products without having a strategy in place to keep them working with up-to-date security. It is also up to the user to keep their router’s firmware up-to-date - something that is very easy to not keep top-of-mind. Plus, some routers make firmware updates time-consuming and difficult.

To attack the network, hackers seek to change the DNS server setting on your router. When you try to connect to a secure website, the malicious DNS server tells you to go to an elaborately constructed phishing site instead. By spoofing the domain and rerouting you to a website that is specifically constructed to take advantage of you, you have very little chance of warding off the attack before it’s too late.

Hackers have also been known to inject all types of user hindrances such trying to perform drive-by downloads, or inundating users with advertisements. Many attacks make use of cross-site request forgery attacks where a malicious actor creates a rogue piece of JavaScript that repeatedly tries to load the router’s web-admin page and change the router’s settings.

What to Do If This Happens to You
The first thing you should do is work to ascertain if your router has been compromised. You can do this in several ways, but the most telling is that your DNS server has been changed. You’ll have to access your router's web-based setup page. Once in, you have to visit the Internet connection screen. If your DNS setting is set to automatic, you are in the clear. If it’s set to “manual”, however, there will be custom DNS servers entered in the space. Many times, this is the first sign of a problem.

If you have been compromised, ensuring your router is set up to your manufacturer’s specifications will help you mitigate damage. To ward against this happening to you, you should always:

  • Install firmware updates: Making sure your router’s firmware is updated to the latest version will definitely help.
  • Disable remote access: Stop remote access to secure against anyone changing settings on your networking equipment.
  • Turn off UPnP: Plug and play can be very convenient, but your router could be affected through UPnP if there is any malware on the network since it is designed to universally trust all requests.
  • Change credentials: Changing your passwords are a simple way of keeping unwanted entities out of your router.

For more information about network and cybersecurity, the expert technicians at Total Tech Care are accessible and ready to help you keep your network and infrastructure secure. For help, call us at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Tuesday, 23 April 2024
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Network Security Business Google Microsoft Internet Email Malware Workplace Tips Backup Innovation User Tips Data Computer Mobile Devices IT Services Hardware Disaster Recovery Android VoIP communications Business Continuity IT Support Smartphones Communication Smartphone Miscellaneous Mobile Device Small Business Network Browser Collaboration Productivity Cybersecurity Quick Tips Users Business Management Phishing Upgrade Windows Managed IT Services Outsourced IT Ransomware Data Backup Windows 10 Cloud Computing Office Data Recovery Server Save Money Windows 10 Passwords Social Media Saving Money Holiday Gadgets Chrome Virtualization Tech Term Managed IT Services Microsoft Office Managed Service Automation Cybercrime Operating System Artificial Intelligence Computers Facebook BYOD Mobile Device Management Health Networking Internet of Things IT Support Hacking Wi-Fi Remote Managed Service Provider Alert Spam Covid-19 Information Office 365 Telephone Systems Information Technology Router Recovery Employer-Employee Relationship Bandwidth BDR Social Engineering Mobility Application Human Resources Law Enforcement Data Breach Remote Monitoring Big Data Password Money App History Encryption Mobile Computing Applications VPN Government Data Storage Patch Management Remote Computing Private Cloud Blockchain Paperless Office Mobile Office Managed IT Apps Office Tips How To Training Website Gmail Budget Settings Avoiding Downtime Vulnerability Two-factor Authentication Windows 7 Word Mouse HaaS Servers Bring Your Own Device Data Management Work/Life Balance Infrastructure Voice over Internet Protocol Flexibility Data Security Marketing Wireless WiFi IT solutions Entertainment Google Drive Sports HIPAA Data Protection Redundancy USB Keyboard Firewall Conferencing Virtual Reality Scam Apple Vendor Social Managed Services Save Time Software as a Service Display Telephone System Staff User Error Machine Learning Vendor Management Meetings Connectivity Remote Work Cleaning Employee/Employer Relationship RMM Risk Management Hacker End of Support Education Physical Security The Internet of Things Lithium-ion battery Safety PDF Cryptocurrency Customer Service Hiring/Firing Proactive IT Procurement Environment Comparison Net Neutrality Workplace Strategy Best Practice Fax Server IT Consultant YouTube CES Help Desk Black Market Printing Humor SaaS Business Technology Business Intelligence Content Management Access Control Audit Managed Services Provider Worker Document Management Solid State Drive Wireless Technology Virtual Assistant IT Management Network Congestion Authentication Database How to Downtime eWaste Botnet IT Plan Remote Workers Data storage Processor Automobile Update Unsupported Software Wearable Technology Computing Infrastructure Retail Hard Drive Charger Hard Drives Google Docs Going Green Virus Instant Messaging Robot Identity Theft Compliance Excel Unified Threat Management OneNote Computer Care Computer Accessories Computing Current Events Biometrics Virtual Desktop Battery Telephony Shadow IT Samsung Legal Augmented Reality Fraud DDoS Internet Exlporer Value Digital Signage Remote Worker Printer SharePoint Spam Blocking Electronic Medical Records Bluetooth Procedure Screen Mirroring Recycling Saving Time Loyalty Analyitcs Programming Google Search Books Wiring dark theme Printer Server Frequently Asked Questions Practices Shopping Cache AI Windows 10s Amazon Web Services IT Infrastructure Relocation Mobile Safe Mode FinTech Cast Criminal Bing Emergency Video Games GDPR Tip of the week Antivirus Hosted Computing Social Network webinar Professional Services Wireless Internet Public Cloud Online Shopping Investment Employer Employee Relationship Windows 8 Worker Commute File Sharing Employees IT service Employee/Employer Relationships Assessment Experience Specifications ISP Scalability Camera Windows 365 Windows Server 2008 Inventory Tools Wire Video Conferencing Evernote ROI Tablet Business Owner NarrowBand Sales Domains Bitcoin Television Travel Shortcuts Millennials Cryptomining Search Printers Point of Sale Personal IaaS Smart Office Supply Chain Management Maintenance Wireless Charging iPhone Consultant Monitoring Batteries Public Computer Bloatware Digitize Workforce Transportation Virtual Private Network Windows 8.1 Analytics Regulations Computer Fan Cables Windows Server 2008 R2 Rootkit Tablets Files Best Available Chromecast Customer relationships Entrepreneur Nanotechnology IT Assessment Workers Telecommuting Manufacturing Benefits WIndows 7 Project Management Email Best Practices Colocation Uninterrupted Power Supply FENG Shortcut Cortana Security Cameras Computer Tips Digital Signature Managed IT Service IBM Cost Management OneDrive Social Networking Biometric Security Smart Technology Monitor Warranty Virtual CIO Flash HVAC Peripheral Google Apps Digital Security Cameras Software Tips Analysis Using Data Supercomputer Streaming Media Devices Copiers Windows Media Player Emails 5G User Reputation Administrator PowerPoint Sync Running Cable Tech Support Enterprise Content Management Quick Tip Memory Content Smartwatch Techology Laptop MSP Ergonomics Accountants Thought Leadership Development Netflix Credit Cards OLED Two Factor Authentication Managing Stress Customers Microchip Password Management PCI DSS Root Cause Analysis Password Manager Virtual Machine Audiobook Multi-Factor Security Employee Music Touchpad 2FA Cameras HBO Fiber Optics Knowledge Twitter Messaging Cabling Science Search Engine Skype Advertising NIST Policy Data loss Business Mangement Hypervisor Politics Trending Troubleshooting Dark mode Outlook Smart Tech Trend Micro Leadership Distributed Denial of Service Notifications Addiction SMS Customer Relationship Management Amazon Default App Start Menu

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code