Site icon WinCert

Hackers infecting routers with Covid-19 malware

<p>And while the whole world is fighting against the COVID-19 virus&comma; a new threat appeared on the internet carrying its name&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3460" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;03&sol;hacking-2903156&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"426" &sol;><&sol;p>&NewLine;<p>This new type of attack involves several stages that start by taking control of home and small business Linksys and D-link routers using a brute force attack&period;<&sol;p>&NewLine;<p>Once attackers gain control over the router they can change the default DNS server&period; The new DNS server will work normally for most of the web addresses&comma; but for some designates sites&comma; the victims will be redirected to a bogus site&period;<&sol;p>&NewLine;<p>The bogus site will look completely normal&comma; but unlike the real site&comma; it will additionally offer a pop-up window that will ask permission to install an app from the World Health Organization which gives the latest information about the COVID-19 virus&period;<&sol;p>&NewLine;<p>Domains that are included in this campaign include aws&period;amazon&period;com&comma; goo&period;gl&comma; bit&period;ly&comma; washington&period;edu&comma; imageshack&period;us&semi; ufl&period;edu&comma; disney&period;com&semi; cox&period;net&comma; xhamster&period;com&comma; pubads&period;g&period;doubleclick&period;net&comma; tidd&period;ly&comma; redditblog&period;com&comma; fiddler2&period;com&comma; winimage&period;com&period;<&sol;p>&NewLine;<p>Of course&comma; this COVID-19 app actually is a malware that once installed can gather private information like login data and send it back to attackers&period;<&sol;p>&NewLine;<p>To stay protected&comma; users are advised to disable remote access to their routers from the Internet&period; If this feature is really needed&comma; users are advised to use complex passwords that should help against brute force attacks&period; Along with this&comma; it is also recommended to keep the router software&sol;firmware up to date&period;<&sol;p>&NewLine;

Exit mobile version