We have already reported on the widespread cyberattack on over 200,000 MikroTik routers by malicious users, using a vulnerability revealed in the CIA Vault 7.
Now, Chinese security researchers at Qihoo 360 Netlab have discovered that out of 370,000 potentially vulnerable MikroTik routers, over 7,500 devices have been compromised to allow malicious users to forward Socks4, allowing attackers to actively monitor network traffic.
The vulnerability in question concerns Winbox Any Directory File Read (CVE-2018-14847) in MikroTik routers and was found to exploit the CIA Vault 7 hacking tool called Chimay Red, along with MikroTik's Webfig remote code execution vulnerability.
Both Winbox and Webfig manage RouterOS with their respective communication ports such as TCP/8291, TCP/80, and TCP/8080. Winbox is designed for Windows users who can easily configure routers that download DLL files from the router and run them on a system.
According to researchers, more than 370,000 MikroTik routers are still vulnerable to CVE-2018-14847, even after the relevant security updates were released to close the gap.

Netlab researchers have identified malware that exploits the CVE-2018-14847 vulnerability to perform various malicious actions, including injecting CoinHive mining code, implicitly enabling Socks4 proxy on routers, and spying on victims.
CoinHive Mining Code Injection – After enabling the Mikrotik RouterOS HTTP proxy, attackers redirect all HTTP proxy requests to a local HTTP 403 error page that inserts a link to the web mining code from Coinhive.
Maliciously Enabling Sock4 Proxy – Implicitly enabling the Socks4 port or TCP/4153 device on victim systems allows an attacker to gain control even after reboot (IP change) by periodically reporting the last IP address in the attacker's URL.
Eavesdropping on Victims – Since MikroTik RouterOS devices allow users to capture packets on the router and forward them to the designated Stream server, attackers forward traffic from compromised routers to IP addresses controlled by them.
The victims are scattered across various countries such as Russia, Iran, Brazil, India, Ukraine, Bangladesh, Indonesia, Ecuador, United States, Argentina, Colombia, Poland, Kenya, Iraq and some European and Asian countries in addition.
Netlab did not share the victims' IP addresses with the public for security reasons, but said relevant security agencies in the affected countries can contact the company for a full list of infected IP.
The best way to protect yourself is to patch your device. MikroTik RouterOS users are strongly encouraged to update their devices and also check whether the HTTP, Socks4 proxy, and network traffic capture feature are being exploited by malicious packets.
