Bonus $100
Fury vs Usyk
IPL 2024
Paris 2024 Olympics
PROMO CODES 2024
PSG vs Borussia Dortmund
UEFA Euro 2024
Users' Choice
88
87
85
69

199 compromised Cisco routers found worldwide

23 Sep 2015
00:00
Read More

The malware that FireEye's Mandiant found on a dozen or two Cisco routers spread around the world isn't quite as limited as initially thought.

Cisco and the volunteer security group called the Shadowserver Foundationsaid today that the malware has now been found on some 199 older Cisco routers in 31 countries.

SYNful Knock has cropped up across an even more widespread footprint, including dozens of servers located in the USA.

Basically, it's a replacement image of the router's operating system, one that lets a remote entity do basically whatever it wants with the system. It's basically a giant backdoor maintenance utility.

What it isn't is a virus or trojan or anything like that. It's something that can only be installed via root access, which means the attacker already had complete control -- he just wanted to make it easier to use for future projects/missions.

Nobody knows what if anything was eavesdropped on, nor is anyone saying just who would have not only built such a beast, but deployed it as well. But the nature and flexibility of the tool says pretty clearly it's not garage-based hackers messing around with personal details and such.

That's not to say such people couldn't do it, it's just that they wouldn't likely do it this way. This sounds like a nation state, and the two biggest suspects would be the NSA and the Chinese, depending on the flavor of your own personal paranoia.

If someone has done this for certain routers, you can be sure they've at least tried it for others, and not just Cisco. They may even have succeeded and just not been detected yet. A whole new front seems to be opening up in the never-ending cybersecurity war.

This article was authored by Rob Powell and was originally posted on Telecomramblings.com

Rob Powell is founder & editor of Telecom Ramblings, which was set up in 2008. The website is dedicated to discussing trends and developments in the telecom industry.

.

Related content

Rating: 5
Advertising