Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Your Router Can Host Some Pretty Nasty Malware

Your Router Can Host Some Pretty Nasty Malware

Hundreds of millions of people use wireless Internet connections every day, and as a result, hackers are taking that as a challenge. They are now starting to develop malware that targets people through their routers. Recently, security researchers at Kaspersky Lab have discovered the malware named Slingshot. The code is designed to spy on PCs through a multi-layer attack that targets MikroTik routers. Today we take a look at Slingshot, and other router-based malware and what you can do about it.

Slingshot
Slingshot works by replacing a library file with a malicious version that downloads more malicious components and then eventually launches a two-front attack on the computers connected to it. The first one runs low-level kernel code that gives an intruder free rein of a system, while the other focuses on the user level and includes code to manage the file system and keep the malware alive.

It is a very intricate attack that calls the nefarious code in from an encrypted virtual file system; managing to do so without crashing the host system, a feat not lost on the security experts at Kaspersky Lab, who deemed it a state-sponsored attack because of the quality of the overall attack and the complexity of its components. Reports suggest that the malware can basically steal whatever it wants, including keyboard strokes, passwords, screenshots, and information about network usage and traffic.

MikroTik has announced that they have patched the vulnerability on versions of their routing firmware, but concerns remain as no one is sure if other router manufacturers have been affected. If that were to come to fruition, Slingshot could be a much larger problem than is currently believed.

Other Instances
Slingshot isn’t the first instance of a router turning on its owner. Traditionally, router security is known to be largely unreliable. Much of this is on the manufacturers, which have been known to build many different products without having a strategy in place to keep them working with up-to-date security. It is also up to the user to keep their router’s firmware up-to-date - something that is very easy to not keep top-of-mind. Plus, some routers make firmware updates time-consuming and difficult.

To attack the network, hackers seek to change the DNS server setting on your router. When you try to connect to a secure website, the malicious DNS server tells you to go to an elaborately constructed phishing site instead. By spoofing the domain and rerouting you to a website that is specifically constructed to take advantage of you, you have very little chance of warding off the attack before it’s too late.

Hackers have also been known to inject all types of user hindrances such trying to perform drive-by downloads, or inundating users with advertisements. Many attacks make use of cross-site request forgery attacks where a malicious actor creates a rogue piece of JavaScript that repeatedly tries to load the router’s web-admin page and change the router’s settings.

What to Do If This Happens to You
The first thing you should do is work to ascertain if your router has been compromised. You can do this in several ways, but the most telling is that your DNS server has been changed. You’ll have to access your router's web-based setup page. Once in, you have to visit the Internet connection screen. If your DNS setting is set to automatic, you are in the clear. If it’s set to “manual”, however, there will be custom DNS servers entered in the space. Many times, this is the first sign of a problem.

If you have been compromised, ensuring your router is set up to your manufacturer’s specifications will help you mitigate damage. To ward against this happening to you, you should always:

  • Install firmware updates: Making sure your router’s firmware is updated to the latest version will definitely help.
  • Disable remote access: Stop remote access to secure against anyone changing settings on your networking equipment.
  • Turn off UPnP: Plug and play can be very convenient, but your router could be affected through UPnP if there is any malware on the network since it is designed to universally trust all requests.
  • Change credentials: Changing your passwords are a simple way of keeping unwanted entities out of your router.

For more information about network and cybersecurity, the expert technicians at Total Tech Care are accessible and ready to help you keep your network and infrastructure secure. For help, call us at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 28 February 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Business Google Network Security Microsoft Internet Email Malware Workplace Tips Backup Innovation Data User Tips Computer Mobile Devices IT Services Hardware Disaster Recovery Android VoIP communications Business Continuity Communication IT Support Smartphones Smartphone Miscellaneous Mobile Device Small Business Network Browser Productivity Collaboration Cybersecurity Quick Tips Business Management Users Phishing Upgrade Managed IT Services Windows Data Backup Outsourced IT Ransomware Windows 10 Cloud Computing Office Server Save Money Data Recovery Passwords Windows 10 Gadgets Tech Term Saving Money Holiday Social Media Chrome Virtualization Automation Microsoft Office Managed Service Managed IT Services Artificial Intelligence Facebook Cybercrime Operating System Computers BYOD Mobile Device Management Wi-Fi Networking IT Support Health Hacking Internet of Things Telephone Systems Alert Information Technology Remote Managed Service Provider Covid-19 Information Spam Office 365 Bandwidth Recovery Employer-Employee Relationship Social Engineering Mobility Router BDR App History Application Password Money Encryption Data Breach Human Resources Big Data Applications Remote Monitoring Law Enforcement Mobile Computing Managed IT Office Tips Training Data Storage Patch Management Apps VPN Remote Computing Blockchain Paperless Office Mobile Office Government How To Private Cloud Website Budget Wireless Bring Your Own Device Data Management Work/Life Balance Vulnerability Gmail Windows 7 Settings Word Servers Two-factor Authentication Google Drive Mouse HaaS Data Security Avoiding Downtime Flexibility Marketing WiFi Infrastructure Voice over Internet Protocol IT solutions Entertainment Save Time Risk Management Hacker USB The Internet of Things Cleaning Lithium-ion battery Data Protection Conferencing Scam End of Support Firewall Physical Security Education Safety Vendor Management Virtual Reality Vendor HIPAA Apple Sports Redundancy Managed Services Display Keyboard Telephone System Social Staff Software as a Service Machine Learning User Error Connectivity Remote Work Meetings Employee/Employer Relationship RMM Biometrics Augmented Reality Virtual Desktop Data storage Fraud Hiring/Firing Automobile Digital Signage DDoS Remote Worker IT Consultant SharePoint Cryptocurrency Computing Infrastructure Going Green Humor Procurement Business Intelligence Comparison Net Neutrality Customer Service Workplace Strategy Environment Audit Battery Worker Help Desk CES Shadow IT IT Management Printing Legal Fax Server Botnet IT Plan Business Technology Content Management Internet Exlporer SaaS Access Control Managed Services Provider Unsupported Software Virtual Assistant PDF Database Authentication Charger Network Congestion eWaste Proactive IT Virus Remote Workers Compliance Computer Care Best Practice Unified Threat Management Processor OneNote Current Events YouTube Computer Accessories Update Black Market Telephony Samsung Hard Drive Google Docs Wearable Technology Hard Drives Identity Theft Retail Document Management Value Instant Messaging Computing Solid State Drive Robot Wireless Technology Excel Printer Downtime Spam Blocking How to Electronic Medical Records Bluetooth Loyalty Password Management Files Password Manager PCI DSS Virtual Machine Screen Mirroring Multi-Factor Security Fiber Optics Frequently Asked Questions Employee Books Chromecast 2FA Printer Server Twitter Messaging Mobile Cabling Windows 10s Search Engine NIST Colocation Business Mangement Uninterrupted Power Supply Policy Hypervisor Cast Trending Trend Micro Tip of the week webinar Emergency Smart Tech Dark mode Science Addiction Monitor Amazon SMS Professional Services Default App Public Cloud Employer Employee Relationship Assessment Recycling Procedure Saving Time Shopping Windows Server 2008 Google Search Distributed Denial of Service Wiring Customer Relationship Management Practices dark theme Cache Reputation Analyitcs Amazon Web Services Streaming Media AI Tools IT Infrastructure Bing Content Television Safe Mode Programming Criminal Tech Support FinTech Social Network GDPR Techology Hosted Computing Laptop Wireless Internet Customers Online Shopping Investment Audiobook Public Computer Antivirus File Sharing Consultant Employees Employee/Employer Relationships Windows 8 Analytics Specifications Regulations ISP Camera Transportation Inventory Touchpad Windows 365 IT service Wire Evernote Video Conferencing ROI Computer Fan Rootkit Shortcuts Politics Advertising Best Available Sales Travel Bitcoin Tablet Millennials Personal Cryptomining Workers Printers Benefits WIndows 7 Point of Sale Domains Smart Office Wireless Charging Notifications Supply Chain Management FENG IBM Monitoring Batteries Workforce Digitize Flash IaaS Virtual Private Network Smart Technology Maintenance Windows 8.1 Relocation Bloatware Cables Windows Server 2008 R2 Software Tips Supercomputer Customer relationships Email Best Practices Tablets PowerPoint Telecommuting IT Assessment Sync Windows Media Player Manufacturing Emails Project Management Video Games User Nanotechnology Worker Commute Entrepreneur Cortana Managed IT Service Security Cameras Experience Digital Signature Computer Tips Virtual CIO OneDrive Biometric Security Netflix Warranty Scalability Two Factor Authentication Shortcut Managing Stress Business Owner HVAC Cost Management Google Apps Peripheral Root Cause Analysis Using Data HBO Knowledge Music Social Networking Analysis NarrowBand Digital Security Cameras Cameras Devices Copiers Skype 5G Administrator Search Enterprise Content Management iPhone Quick Tip Data loss Outlook Smartwatch Leadership Running Cable MSP Troubleshooting Accountants Ergonomics Thought Leadership Memory Credit Cards Development Start Menu OLED Microchip

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code