HomeSecurityMalware uses WiFi BSSID to find victims' location

Malware uses WiFi BSSID to find victims' location

Malware operators have found a new way to track the location of their victims by collecting the WiFi BSSID (WiFi AP MAC address).

WiFi BSSID location
Malware uses WiFi BSSID to find victims' location

Cybercriminals often want to know the location of the victims they infect with malware , and they usually do this by using a simple technique that collects the victim's IP address. They then check the address against an IP-to-geo database, such as MaxMind's GeoIP. Thanks to this database, hackers can learn the approximate geographic location of the victim.

This technique is not completely accurate, but it is still the most reliable method of determining a user's physical location, based on the data located on their computer.

However, last month, Xavier Mertens, a security, said he discovered a new malware that uses a second technique along with the first.

This second technique is based on “snatching” the infected user’s BSSID.

Known as “Basic Service Set Identifier”, BSSID is basically the physical MAC address of the wireless router or access point that the user uses to connect via WiFi.

You can view the WiFi BSSID on Windows by running the command:

netsh wlan show interfaces | find “BSSID”

According to the security, the new malware collects the WiFi BSSID and then checks it against a free BSSID-to-geo database, maintained by Alexander Mylnikov.

Malware uses WiFi BSSID to find victims' location
Malware uses WiFi BSSID to find victims' location

This database includes a collection of known BSSIDs and the last geographic location at which they were detected.

These databases are often used by mobile app operators as alternative ways to track userswhen they cannot directly access a phone's location data.

Checking the WiFi BSSID in Mylnikov's database allows malware operators to determine the geographic location of victims, since the location of the WiFi access point the victim uses to connect to the internet.

Using the above two techniques simultaneously offers higher success rates in locating the victim. If both techniques result in the same location, then hackers can be sure.

Malware operators are interested in the geographic location of their victims because some want to target only specific countries or do not want to infect users from their home country (in order to avoid the attention of local authorities).

However, IP-to-geo databases are not accurate, as telecommunications companies and data centers tend to rent IP address blocks on the open market. This results in some IP blocks being assigned to different organizations, in other regions of the world, from their original/actual owner.

Using a second method to double-check a victim's geographic location has not yet been widely adopted. However, it would certainly be very helpful, so many hacking groups may take advantage of it in the future.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS