Hackers of all kinds are attacking routers across the world

hackers of all kinds are attacking routers across the world

Hackers of all kinds are attacking routers across the world

When hackers find a vulnerable router, they compromise it by installing malware that grants persistence, the ability to run distributed denial of service (DDoS) attacks, hide malicious traffic, and more. But what happens when the hackers find a router that was already compromised by a rival gang?

Cybersecurity researchers from Trend Micro published a report that found that one of two things happen: either one group allows the other one to use the compromised infrastructure for a fee, or they each find a different way to break into the device and they use them simultaneously.

Trend Micro’s researchers made an example out of Ubiquity’s EdgeRouters, internet routers that were abused by a handful of hacking groups at the same time, some being state-sponsored, and others being financially-driven.

Shared co-working spaces

“Cybercriminals and Advanced Persistent Threat (APT) actors share a common interest in proxy anonymization layers and Virtual Private Network (VPN) nodes to hide traces of their presence and make detection of malicious activities more difficult,” the researchers explained. “This shared interest results in malicious internet traffic blending financial and espionage motives.”

When it comes to Ubiquity, Trend Micro researchers said they observed the endpoints being used by the APT28 threat actor for “persistent espionage campaigns.” APT28 is a Russian state-sponsored group, also known as Fancy Bear, or Pawn Storm. At the same time, they also saw a financially motivated group called the Canadian Pharmacy gang, using the same infrastructure to mount pharma-related phishing campaigns. Finally, they observed the Ngioweb malware being loaded directly into the memory of these devices – malware that was attributed to the Ramnit group.

EdgeRouters were a popular target mostly because the victims kept them either poorly defended, or entirely undefended. However, they don’t stand out much from other routers, which are all an equally popular asset for hackers. This is because generally they have reduced security monitoring, less stringent password policies, are rarely updated, and run on powerful operating systems that can be used for a wide number of things, Trend Micro concluded.

More from TechRadar Pro

    OTHER NEWS

    12 minutes ago

    Triple whammy virus cocktail smashing Victoria and NSW

    12 minutes ago

    Podcast: 489kW Vantage driven, EV prices slashed

    12 minutes ago

    Workers taking on second jobs as cost pressures build

    12 minutes ago

    Everything announced at Microsoft's Copilot and Surface event

    12 minutes ago

    Citizens face hours-long blackout as major cities are scorched by record-breaking heat wave: 'This was something exceptional'

    12 minutes ago

    Mining industry in a ‘vulnerable position’ if it needs to ‘rely on government handouts’

    12 minutes ago

    Australia ‘needs to invest’ in ‘reliable power systems’

    14 minutes ago

    SWAT Season 7 Finale: Deacon Finally Rejoins 20-Squad & It's A Big Mistake

    17 minutes ago

    Wrestling star dies aged 40 - just nine days after his final match

    17 minutes ago

    Today viewers call out newsreader Brooke Boney's 'odd' accent: 'Some days it's stronger than others'

    17 minutes ago

    Dr Chris Brown RESIGNS from his new gig Dream Home live on-air: 'Someone get Channel Seven on the phone'

    17 minutes ago

    Meal-planning expert reveals the tasty dishes you can make for just $2.50 per serve that the whole family will love

    17 minutes ago

    Juneteenth proclaimed state holiday again in Alabama, after bill to make it permanent falters

    17 minutes ago

    Donald Trump hush money trial nears its conclusion

    18 minutes ago

    Monks and Muslims vote to demand rights for India's Ladakh

    19 minutes ago

    Trump: Biden campaign put out ‘Fake Story’ that he ‘froze’ during NRA speech

    19 minutes ago

    Baby Reindeer’s ‘Martha’ has now been accused of mass messaging a major politician

    19 minutes ago

    Trump hush money trial: Prosecution rests, judge admonishes defence witness

    19 minutes ago

    Fraser-McGurk named as reserve in Australia’s T20 World Cup squad

    19 minutes ago

    Labor's handling on migration 'unplanned and unmanaged'

    19 minutes ago

    In a BJP stronghold, Jharkhand’s ‘best MLA’ tries to upset the apple cart with RJD help

    19 minutes ago

    ‘Overly simplistic message’: Sam Crosby on Peter Dutton’s migration plan

    19 minutes ago

    Elvis' Graceland faces foreclosure auction; granddaughter Riley Keough sues to block sale

    19 minutes ago

    Biden and Democrats raised $51 million in April, far less than Trump and the GOP's $76 million

    19 minutes ago

    Labor’s ‘simplistic claims’ about public servant numbers ‘precisely disproved’ by the evidence

    19 minutes ago

    AMC triggers backlash for adding warning to 'Goodfellas' for stereotypes that don't match modern 'inclusion'

    20 minutes ago

    How to safely use generators when the power goes out

    23 minutes ago

    Roosters NRL club lashes out in fury as video of four stars in hotel room goes viral on social media

    23 minutes ago

    Anti-woke American Matt Walsh takes another swipe at Australia

    24 minutes ago

    FDIC chairman Martin Gruenberg resigns after report found toxic workplace culture inside the banking regulator

    24 minutes ago

    Tesla factory fire: Smoke seen rising from Elon Musk's Fremont plant

    25 minutes ago

    Top U.S. natural gas producer Chesapeake Energy cuts jobs

    25 minutes ago

    Trump entourage at Manhattan courthouse on Monday includes Bernie Kerik and Chuck Zito

    25 minutes ago

    How to unlock Stellar Blade's Forbidden Area

    25 minutes ago

    How Malcolm Brogdon helped build both Eastern Conference finalists

    25 minutes ago

    The Matildas’ summer Olympics 2024 guide

    26 minutes ago

    Tesla shareholders say Elon's influence makes Kimbal Musk and James Murdoch unsuitable for the company's board

    26 minutes ago

    South Korea, UK to host AI summit in Seoul as risks mount

    26 minutes ago

    The One Iron Man Armor That's Too Gross For The MCU

    26 minutes ago

    SIA and Garuda to partner on frequent flyer miles

    Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch