Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Your Router Can Host Some Pretty Nasty Malware

Your Router Can Host Some Pretty Nasty Malware

Hundreds of millions of people use wireless Internet connections every day, and as a result, hackers are taking that as a challenge. They are now starting to develop malware that targets people through their routers. Recently, security researchers at Kaspersky Lab have discovered the malware named Slingshot. The code is designed to spy on PCs through a multi-layer attack that targets MikroTik routers. Today we take a look at Slingshot, and other router-based malware and what you can do about it.

Slingshot
Slingshot works by replacing a library file with a malicious version that downloads more malicious components and then eventually launches a two-front attack on the computers connected to it. The first one runs low-level kernel code that gives an intruder free rein of a system, while the other focuses on the user level and includes code to manage the file system and keep the malware alive.

It is a very intricate attack that calls the nefarious code in from an encrypted virtual file system; managing to do so without crashing the host system, a feat not lost on the security experts at Kaspersky Lab, who deemed it a state-sponsored attack because of the quality of the overall attack and the complexity of its components. Reports suggest that the malware can basically steal whatever it wants, including keyboard strokes, passwords, screenshots, and information about network usage and traffic.

MikroTik has announced that they have patched the vulnerability on versions of their routing firmware, but concerns remain as no one is sure if other router manufacturers have been affected. If that were to come to fruition, Slingshot could be a much larger problem than is currently believed.

Other Instances
Slingshot isn’t the first instance of a router turning on its owner. Traditionally, router security is known to be largely unreliable. Much of this is on the manufacturers, which have been known to build many different products without having a strategy in place to keep them working with up-to-date security. It is also up to the user to keep their router’s firmware up-to-date - something that is very easy to not keep top-of-mind. Plus, some routers make firmware updates time-consuming and difficult.

To attack the network, hackers seek to change the DNS server setting on your router. When you try to connect to a secure website, the malicious DNS server tells you to go to an elaborately constructed phishing site instead. By spoofing the domain and rerouting you to a website that is specifically constructed to take advantage of you, you have very little chance of warding off the attack before it’s too late.

Hackers have also been known to inject all types of user hindrances such trying to perform drive-by downloads, or inundating users with advertisements. Many attacks make use of cross-site request forgery attacks where a malicious actor creates a rogue piece of JavaScript that repeatedly tries to load the router’s web-admin page and change the router’s settings.

What to Do If This Happens to You
The first thing you should do is work to ascertain if your router has been compromised. You can do this in several ways, but the most telling is that your DNS server has been changed. You’ll have to access your router's web-based setup page. Once in, you have to visit the Internet connection screen. If your DNS setting is set to automatic, you are in the clear. If it’s set to “manual”, however, there will be custom DNS servers entered in the space. Many times, this is the first sign of a problem.

If you have been compromised, ensuring your router is set up to your manufacturer’s specifications will help you mitigate damage. To ward against this happening to you, you should always:

  • Install firmware updates: Making sure your router’s firmware is updated to the latest version will definitely help.
  • Disable remote access: Stop remote access to secure against anyone changing settings on your networking equipment.
  • Turn off UPnP: Plug and play can be very convenient, but your router could be affected through UPnP if there is any malware on the network since it is designed to universally trust all requests.
  • Change credentials: Changing your passwords are a simple way of keeping unwanted entities out of your router.

For more information about network and cybersecurity, the expert technicians at Total Tech Care are accessible and ready to help you keep your network and infrastructure secure. For help, call us at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 15 January 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Software Efficiency Business Google Network Security Microsoft Internet Email Malware Backup Workplace Tips Innovation User Tips Data Computer Mobile Devices Hardware IT Services Disaster Recovery Android VoIP communications Business Continuity Smartphones Communication IT Support Miscellaneous Smartphone Mobile Device Small Business Network Browser Productivity Collaboration Quick Tips Cybersecurity Business Management Users Windows Phishing Upgrade Managed IT Services Data Backup Outsourced IT Ransomware Windows 10 Office Cloud Computing Server Save Money Data Recovery Windows 10 Passwords Gadgets Virtualization Tech Term Saving Money Holiday Social Media Chrome Managed Service Automation Managed IT Services Microsoft Office Computers Artificial Intelligence Facebook Operating System Cybercrime Wi-Fi BYOD Mobile Device Management Networking IT Support Hacking Internet of Things Health Alert Spam Office 365 Remote Telephone Systems Managed Service Provider Information Technology Covid-19 Information Bandwidth Router Social Engineering BDR Mobility Recovery Employer-Employee Relationship Mobile Computing Password Remote Monitoring Money Application Encryption Applications App History Big Data Law Enforcement Data Breach Human Resources Remote Computing Managed IT Mobile Office Apps How To Office Tips Data Storage Training Patch Management Government Blockchain VPN Paperless Office Private Cloud Flexibility Two-factor Authentication Marketing Infrastructure Bring Your Own Device Voice over Internet Protocol WiFi Data Management Mouse Data Security HaaS IT solutions Work/Life Balance Entertainment Website Budget Google Drive Wireless Vulnerability Avoiding Downtime Windows 7 Gmail Word Settings Servers Save Time Virtual Reality Employee/Employer Relationship Apple RMM Social Cleaning User Error Meetings USB End of Support Data Protection Education Physical Security Risk Management Safety Hacker Sports HIPAA Redundancy The Internet of Things Conferencing Keyboard Lithium-ion battery Vendor Scam Managed Services Telephone System Staff Software as a Service Display Firewall Machine Learning Vendor Management Connectivity Remote Work Unsupported Software Hard Drive SaaS Computer Accessories Google Docs Charger Data storage Identity Theft Automobile Network Congestion Compliance Computing OneNote eWaste Computer Care Computing Infrastructure Current Events Printer Augmented Reality Going Green Telephony Bluetooth Samsung Fraud Remote Worker Digital Signage Wearable Technology Value Battery Hard Drives Shadow IT Retail Cryptocurrency Electronic Medical Records Instant Messaging Legal Spam Blocking IT Consultant Robot Excel Internet Exlporer Procurement Net Neutrality Hiring/Firing Humor Biometrics Workplace Strategy Comparison Virtual Desktop PDF CES Help Desk Printing DDoS Business Technology Content Management Proactive IT SharePoint Access Control Best Practice Business Intelligence Managed Services Provider Virtual Assistant YouTube Database Worker Authentication Black Market Audit IT Management Customer Service Environment Remote Workers Botnet IT Plan Processor Fax Server Virus Document Management Solid State Drive Wireless Technology Update Unified Threat Management How to Downtime Files Google Apps Peripheral IBM HVAC Tablet Domains Smart Technology Analysis Digital Security Cameras Chromecast Flash Using Data Managing Stress 5G Administrator Devices Copiers Colocation Quick Tip Uninterrupted Power Supply Software Tips IaaS Supercomputer Maintenance Cameras Enterprise Content Management MSP Bloatware Accountants Ergonomics Sync Emails Smartwatch OLED Microchip Thought Leadership Monitor Credit Cards Development Tablets Password Manager PCI DSS Virtual Machine Password Management Two Factor Authentication Entrepreneur 2FA Multi-Factor Security Fiber Optics Netflix Employee Streaming Media Root Cause Analysis Cabling Search Engine Twitter Reputation Messaging Business Mangement Policy Tech Support HBO Hypervisor Knowledge Shortcut Music Printer Server Content NIST Cost Management Techology Smart Tech Dark mode Laptop Skype Trending Trend Micro SMS Data loss Default App Social Networking Addiction Customers Amazon Recycling Procedure Outlook Saving Time Leadership Troubleshooting Audiobook Google Search Wiring Practices dark theme Touchpad Start Menu Shopping AI Screen Mirroring IT Infrastructure Running Cable Loyalty Cache Amazon Web Services Memory Advertising Criminal FinTech Frequently Asked Questions Bing Books Politics Safe Mode GDPR Hosted Computing Mobile Social Network Windows 10s Notifications Cast Investment Wireless Internet Online Shopping File Sharing Employees Tip of the week Employee/Employer Relationships webinar Emergency ISP Employer Employee Relationship Camera Inventory Windows 365 Professional Services Specifications Public Cloud Evernote Video Conferencing ROI Assessment Consultant Wire Science Relocation Sales Windows Server 2008 Travel Bitcoin Shortcuts Analytics Cryptomining Printers Video Games Point of Sale Tools Millennials Personal Wireless Charging Supply Chain Management Distributed Denial of Service Television Best Available Customer Relationship Management Worker Commute Smart Office Analyitcs Monitoring Batteries WIndows 7 Experience Virtual Private Network Programming Scalability Windows 8.1 Workforce Digitize Cables Windows Server 2008 R2 Public Computer Business Owner Customer relationships NarrowBand Regulations Transportation Manufacturing Antivirus Rootkit Project Management Search Nanotechnology Email Best Practices Telecommuting IT Assessment Computer Fan Cortana Windows 8 iPhone Windows Media Player Digital Signature Computer Tips Managed IT Service Workers User Security Cameras IT service Benefits PowerPoint FENG Biometric Security Warranty Virtual CIO OneDrive

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code