A security researcher from Team Cymru has discovered a Pharming attack campaign that has targeted home and small office (SOHO) routers. So far, over 300,000 SOHO routers have been compromised.
The hackers changed the DNS settings to set the IP addresses '5.45.75[.]11' and '5.45.75[.]36' on the compromised devices and redirect the victim to the attackers' website.
Most of the compromised devices belong to Vietnam. India is also one of the countries affected by the attack, as are Italy, Thailand, Indonesia, Ukraine, Turkey, and Colombia.
A large number of router manufacturers, including Micronet, Tenda, D-Link, and TP-Link, have been affected by the attack. Researchers say that these devices are also vulnerable to multiple exploits, including CSRF attacks and a vulnerability in the ZyXEL firmware.
The vulnerability in ZyXEL ZynOS, which allows an attacker to directly download the router's configuration settings file https://[IP Address]/rom-0, was discovered by a researcher in January.
So far, the attackers do not appear to have misused the compromised devices, but this attack is similar to that carried out on many banking organizations in Poland.

