For about a year now, Brazilian users have been targeted by hackers , who are using a new type of router attack that has not been seen anywhere else.
Users are unaware of the attacks, yet they are very dangerous, as they can lead to immediate financial losses.
This should be seen as a warning to both users and ISPs around the world to take precautions and protect devicesbefore the attacks spread to other countries.
Router DNS-changing attacks
The attacks on Brazilian routers began last summer and were detected by two firms .
At the time, hackers had infected over 100,000 routers in homes in Brazil, modifying their DNS settings.
These changes redirect users to malicious websiteswhile they are trying to access e-banking sites of certain Brazilian banks.
They also redirect users to phishing sites that supposedly lead to Netflix, Google, and PayPal. In reality, hackers use these sites to steal users' credentials
According to a report by Avast, the attacks haven't stopped. In the first half of 2019, hackers modified the DNS settings of more than 180,000 routers in Brazil. In fact, the attacks have become more sophisticated.

How are attacks carried out?
According to researchers, most routers are compromised when users visit sports and movie sites.
These sites contain malicious adsthat run special code in the browser that searches for and detects the IP address and model of a home router. Once these two elements are detected, the malicious ads use a list of default usernames and passwords to log in to the users' devices.
The attacks go unnoticed because users are busy watching movies.
If the attacks are successful, then other malicious code will be added, which will modify the default DNS settings on the victims' routers, replacing the DNS server IP addresses that the routers receive from their ISPs with IP addresses managed by the hackers.
So, the next time the smartphone or computer connects to the router, it will receive the malicious IP addresses and hackers will be able to redirect users to malicious sites.
GhostDNS, Navidade and SonarDNS
According to Avast, hackers are using two specific kits for these attacks. The first is called GhostDN. A variant of GhostDNS, called Navidade, also appeared in February.
According to Avast, “ Novidade attempted to infect Avast users’ routers over 2.6 million times in February alone.”
The second kit is called SonarDNS. It is ideal for determining the router type and exploiting targeted devices.
Additionally, the attacks replace legitimate ads with others, which generate profits for the attackers and introduce cryptominers to steal users' cryptocurrencies
Risk of spread to other countries
DNS modification attacks are among the most dangerous, as they can be used to steal money from users' bank accounts and are difficult to detect.
Hackers make a lot of money through these attacks, which is why it's a mystery why they haven't spread to other countries.
Users who want to stay safe can follow the following tips:
- Use complex passwords
- Update routers
- Use custom DNS settings on routers
