HomeSecurityMicrosoft creates tool to scan MikroTik routers for malware infections...

Microsoft creates tool to scan MikroTik routers for TrickBot infections

Microsoft has released a scanner that detects MikroTik routers that have been compromised by the TrickBot gang to act as proxies for command and control servers.

See also: CafePress: Former owner fined for ongoing data breaches

Microsoft creates tool to scan MikroTik routers for TrickBot infections

TrickBot is a botnet of malware that is typically distributed via phishing emails. Once executed, TrickBot will connect to a remote command and control server to receive commands and download further payloads to execute on the infected machine.

For years, TrickBot has been using IoT devices, such as routers, to act as proxies between an infected device and its command and control (C2) servers. These proxies are used to prevent researchers and law enforcement from finding and disrupting its command and control infrastructure.

See also: MikroTik: How to protect routers affected by the Mēris botnet

In a new report from Microsoft, researchers explain how the TrickBot gang targeted vulnerable MikroTik routers using various methods to embed them as proxies for C2 communications.

Malicious traffic routing

TrickBot operations used various methods when hacking into MikroTik routers, starting with using default credentials and then performing brute force attacks to guess the password.

If these initial methods did not provide access to the router, threat actors would attempt to exploit CVE-2018-14847, a critical directory traversal vulnerability that allows unauthenticated, remote attackers to read arbitrary files. Using this vulnerability, threat actors would steal the “user.dat” file, which contains the user credentials for the router.

Once they gained access to the device, the threat actors used built-in '/ip', '/system', or '/tool' commands to create a network address translation (NAT) that rerouted traffic sent to port 449 on the router port to port 80 on a remote command and control server.

Microsoft creates tool to scan MikroTik routers for TrickBot infections

By using this IP NAT rule, C2 servers are not directly exposed to threat analysis, but still allow communication for infected devices.

Microsoft MikroTik

As Microsoft highlights, the hackers appear to have in-depth knowledge of the limited functionality of the Linux-based operating system on MikroTik devices, using custom SSH commands that would not make sense on other devices.

The MikroTik problem

A report by Eclypsium highlighted last December that too many MikroTik routers are still vulnerable to malware botnets, several years after the vendor warned of the existence of critical flaws.

Because these devices have unusually powerful hardware, they are considered high-value targets by malicious actors, especially those interested in resource-intensive operations, such as DDoS.

Although security upgrades have been available for years, many devices remain vulnerable to botnet recruitment with hackers exploiting flaws for unauthenticated, remote access and code execution.

See also: 300,000 MikroTik devices still vulnerable to botnets

MikroTik device owners have been repeatedly urged to upgrade to RouterOS versions newer than 6.45.6 and avoid exposure of the WinBox protocol.

Microsoft has now released a tool called "routeros-scanner" that network administrators can use to scan MikroTik devices for signs of being compromised by TrickBot.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS