
A hacking group is targeting home routers and changing the data flow, with the aim of redirecting users to malicious sites.
Hackers are exploiting vulnerabilities in router firmware, mainly in D-Link models, to break into vulnerable devices and make changes to the DNS , which most users are unable to notice.
The router models affected by the hacking are the following:
D-Link DSL-2640B – 14,327
D-Link DSL-2740R-379
D-Link DSL-2780B – 0
D-Link DSL-526B – 7
ADSL Routers ARG-W4 – 0
DSLink 260E Controllers – 7
Secutech routers – 17
TOTOLINK Routers – 2,265
A security researcher and founder of the company Bad Packets, Troy Mursch, said that hackers have launched attacks on router DNS settings since December 2018, early February 2019, and late March 2019, and even today the attacks continue.
How attacks work
The purpose of this particular hack was to insert malicious IP addresses into the targeted routers. Mursch said the hackers have used four IP addresses so far. The hackers replaced the IP addresses of legitimate websites with the IP addresses of malicious sites.
What would such an attack look like?
- The user's computer or smartphone receives incorrect DNS settings from the hacked router.
- The user is trying to access a legitimate website.
- The user's device makes a DNS request to the malicious DNS server.
- The malicious server returns an incorrect IP address for the legitimate website.
- The user is redirected to a "clone" of the legitimate website, where they may be asked to log in and thus share their password with the attackers.
However, it is not yet known which legitimate sites hackers are using to trick users.
These types of attacks are not new. They have occurred before under the name “DNSChanger,” named after the first malware that began changing DNS settings in order to redirect users to other locations.
DNSChanger incidents are rare compared to other types of cyberattacks, but they are extremely dangerous and very effective, although easy to detect by Internet monitoring companies like Bad Packets and others.
Regarding the attacks detected by Bad Packets, owners of these devices are advised to check the DNS settings of their routers and compare the DNS IP addresses with those provided by their internet service provider.
However, if you see any of the following four IP addresses, the DNS settings on your router have already been compromised by this hack and you should upgrade your router's firmware as soon as possible.
66.70.173.48
144.217.191.145
195.128.126.165
195.128.124.131
