Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

What is a Router Botnet? Find Out Today!

What is a Router Botnet? Find Out Today!

Ordinarily, one of the best ways to protect your organization’s infrastructure is to make sure any and all patches administered to the software you use are applied as soon as possible after they’ve been released. However, patches don’t help against threats that aren’t discovered at the moment they are released. The recent spread of BCMUPnP_Hunter botnet shows that it’s not enough for people to keep patching their systems.

Threat Background
This botnet was initially discovered in September. Since then, it has infected devices to support a huge spam email campaign. BCMUPnP_Hunter is able to zero-in on victims thanks to its ability to scan for potential targets, like routers with the BroadCom University Plug and Play feature enabled. The system can then be taken over by the hacker.

It is assumed that the network created by BCMUPnP_Hunter was created to send out spam emails. The threat creates a proxy that communicates with email servers, allowing attackers to use botnets to generate profit through fraudulent clicks. What’s more is that the malware seems to have been created by someone who has a considerable amount of skill. To make things worse is that BCMUPnP_Hunter also appears to scan from over 100,000 sources, making this botnet quite large.

How Does This Prove That Patches Aren’t Working?
In order for BCMUPnP_Hunter to work as intended, it must target devices that have BroadcomUPnP enabled to take advantage of a vulnerability. The thing is that this vulnerability has been patched since 2013 when it was first discovered, meaning that most manufacturers have issued a patch since then. Therefore, the majority of devices being used by this threat are those that haven’t been patched for some reason or another.

The Lesson Learned
A simple lesson can be learned here. It goes to show that any equipment on your infrastructure that’s not maintained could be putting your business at risk. This includes making sure that you implement patches and security updates as soon as they are released. Of course, they aren’t always broadcast to the public--after all, who would want to admit that the product they have created is vulnerable to attack, and that the vulnerability is being exploited? As a business owner, it’s your responsibility to keep up with the latest threats.

Granted, not all business owners have the time or luxury to focus on something like this. For those who want to minimize the threat posed by vulnerabilities, give the IT professionals at Total Tech Care a call at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 24 January 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Software Efficiency Google Business Network Security Microsoft Internet Email Malware Backup Workplace Tips Innovation User Tips Data Computer Mobile Devices Hardware IT Services Disaster Recovery Android VoIP communications IT Support Business Continuity Smartphones Communication Miscellaneous Smartphone Mobile Device Browser Small Business Network Collaboration Productivity Cybersecurity Quick Tips Users Business Management Managed IT Services Windows Upgrade Phishing Outsourced IT Data Backup Ransomware Windows 10 Cloud Computing Data Recovery Office Server Save Money Passwords Windows 10 Virtualization Social Media Saving Money Holiday Tech Term Gadgets Chrome Automation Managed Service Managed IT Services Microsoft Office Facebook Artificial Intelligence Computers Cybercrime Operating System Wi-Fi Health BYOD Mobile Device Management Networking IT Support Internet of Things Hacking Remote Information Technology Covid-19 Information Spam Managed Service Provider Office 365 Telephone Systems Alert Employer-Employee Relationship Recovery Bandwidth Router BDR Social Engineering Mobility Password Money Mobile Computing Human Resources Encryption Data Breach Application Applications Remote Monitoring Law Enforcement Big Data App History Managed IT Training Data Storage Patch Management VPN Apps Blockchain Paperless Office Remote Computing Mobile Office Government How To Private Cloud Office Tips Bring Your Own Device Flexibility Data Management Gmail Work/Life Balance Marketing Vulnerability WiFi Settings Windows 7 IT solutions Entertainment Word Website Budget Two-factor Authentication Servers Google Drive Mouse HaaS Infrastructure Avoiding Downtime Data Security Voice over Internet Protocol Wireless The Internet of Things Lithium-ion battery Cleaning Conferencing Scam Vendor Firewall Managed Services End of Support Display USB Education Physical Security Telephone System Staff Virtual Reality Software as a Service Safety Apple Vendor Management Machine Learning Sports HIPAA Employee/Employer Relationship Redundancy Connectivity Social Remote Work Keyboard RMM User Error Meetings Risk Management Hacker Save Time Data Protection Workplace Strategy Hiring/Firing Net Neutrality Data storage DDoS Automobile Unified Threat Management Computer Accessories Help Desk SharePoint Comparison Printing CES Computing Infrastructure Going Green Customer Service Business Technology Business Intelligence Content Management Environment Managed Services Provider Printer Access Control Fax Server Audit Bluetooth Worker Battery Database Shadow IT Virtual Assistant IT Management Remote Workers Legal Authentication SaaS Botnet Internet Exlporer IT Plan Processor IT Consultant Network Congestion Unsupported Software Update Hard Drive PDF eWaste Charger Humor Proactive IT Google Docs Compliance Computing Identity Theft OneNote Computer Care Best Practice YouTube Current Events Black Market Wearable Technology Telephony Retail Hard Drives Samsung Augmented Reality Instant Messaging Fraud Excel Digital Signage Robot Value Document Management Solid State Drive Wireless Technology Remote Worker Biometrics Spam Blocking Electronic Medical Records How to Downtime Virtual Desktop Cryptocurrency Procurement Virus Windows 10s Amazon Web Services User Science Social Network PowerPoint Windows Media Player Mobile Cache Uninterrupted Power Supply Safe Mode Cast Criminal Investment Colocation Emergency Employee/Employer Relationships GDPR Tip of the week Hosted Computing webinar Employees Public Cloud Windows 365 Online Shopping Managing Stress Employer Employee Relationship ISP Monitor Distributed Denial of Service Professional Services Wireless Internet Customer Relationship Management File Sharing Analyitcs Assessment Video Conferencing ROI Bitcoin Cameras Shortcuts Camera Windows Server 2008 Inventory Programming Sales Specifications Point of Sale Evernote Personal Cryptomining Reputation Tools Streaming Media Wire Tech Support Television Supply Chain Management Travel Content Batteries Techology Laptop Printers Antivirus Monitoring Millennials Windows 8.1 Wireless Charging Windows 8 Digitize Customers Smart Office IT service Public Computer Audiobook Windows Server 2008 R2 Transportation Printer Server Touchpad Virtual Private Network Regulations Customer relationships Workforce Computer Fan Email Best Practices Cables Tablet Rootkit IT Assessment Manufacturing Domains Politics Advertising Benefits Managed IT Service Security Cameras Project Management Nanotechnology Workers Computer Tips Telecommuting Maintenance FENG Virtual CIO Cortana OneDrive Biometric Security IaaS Notifications Digital Signature Bloatware IBM Peripheral Smart Technology Using Data Warranty Flash Digital Security Cameras Google Apps Tablets Copiers 5G Relocation HVAC Software Tips Analysis Entrepreneur Supercomputer Quick Tip Video Games Smartwatch Administrator Sync Devices Emails Ergonomics Enterprise Content Management Shortcut Development Worker Commute OLED MSP Accountants Cost Management PCI DSS Experience Consultant Virtual Machine Credit Cards Two Factor Authentication Fiber Optics Scalability Analytics Employee Microchip Thought Leadership Social Networking Netflix 2FA Password Management Root Cause Analysis Password Manager Messaging Business Owner Cabling NarrowBand HBO Knowledge Policy Multi-Factor Security Best Available Music Hypervisor WIndows 7 Trend Micro Search Search Engine Running Cable Skype Twitter Dark mode NIST Data loss Business Mangement Memory SMS Default App iPhone Outlook Smart Tech Leadership Procedure Trending Troubleshooting Saving Time dark theme Amazon Shopping Google Search Start Menu Addiction Screen Mirroring Recycling Loyalty AI IT Infrastructure Files Books Bing Chromecast Wiring Frequently Asked Questions Practices FinTech

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code