Article 51A9X New Attack on Home Routers Sends Users to Spoofed Sites that Push Malware

New Attack on Home Routers Sends Users to Spoofed Sites that Push Malware

by
martyb
from SoylentNews on (#51A9X)

Fnord666 writes:

From ArsTechnica:

A recently discovered hack of home and small-office routers is redirecting users to malicious sites that pose as COVID-19 informational resources in an attempt to install malware that steals passwords and cryptocurrency credentials, researchers said on Wednesday.

A post published by security firm Bitdefender said the compromises are hitting Linksys routers, although BleepingComputer, which reported the attack two days ago, said the campaign also targets D-Link devices.

It remains unclear how attackers are compromising the routers. The researchers, citing data collected from Bitdefender security products, suspect that the hackers are guessing passwords used to secure routers' remote management console when that feature is turned on. Bitdefender also hypothesized that compromises may be carried out by guessing credentials for users' Linksys cloud accounts.

The router compromises allow attackers to designate the DNS servers [that] connected devices use. DNS servers use the Internet domain name system to translate domain names into IP addresses so that computers can find the location of sites or servers users are trying to access. By sending devices to DNS servers that provide fraudulent lookups, attackers can redirect people to malicious sites that serve malware or attempt to phish passwords.

[...] To prevent attacks on routers, the devices should have remote administration turned off whenever possible. In the event this feature is absolutely necessary, it should be used only by experienced users and protected by a strong password. Cloud accounts-which also make it possible to remotely administer routers-should follow the same guidelines. Moreover, people should frequently ensure that router firmware is up-to-date.

Original Submission

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments