A new attack method has been observed by FireEye researchers, in which attackers hide malware inside the firmware of Cisco Routers, malware that is able to survive even after reboots.

Routers and switches are routinely left off security checklists within almost every organization, largely because too few security engineers are educated to know that they can host malware.
This general idea is also reinforced by the fact that most network equipment doesn’t come with hardware to run security software like firewalls, which when combined with a lack of attention from company personnel, can leave a large security hole in a company’s defenses.
Specifically, this new attack method, dubbed SYNful Knock by FireEye researchers, relies on malicious actors gaining access to a router’s login credentials by installing a modified version of IOS, a special operating system developed by Cisco for all of its modern network equipment.
Previous versions of router malware always stored in the device's memory, meaning that rebooting the router would usually clear any infection, since the memory was forgotten during the reboot.
This time, however, by storing their malware in the operating system itself, which is stored on a flash drive rather than RAM, the attackers have created a reusable entry point for their attacks.
This is because the malware provides a backdoor to Cisco, which can be exploited remotely via the console or via Telnet.
But the bad news doesn't end there. In addition to the backdoor, the malware also has the ability to "listen" to router ports, and to listen for specially crafted TCP packets.
This allows attackers to control the router's behavior remotely, sending commands in the form of regular Internet traffic.
With the help of these commands, attackers could make the malware load special modules into the router's memory, which are then used to carry out various types of attacks, such as sniffing traffic, redirecting users to specific websites, or participating in DDOS attacks.
Once these components are loaded into the router's memory, a reboot usually removes them from the infected devices. Unfortunately, this will not stop the attackers, who could load them again very easily.
Finally, according to FireEye researchers, 14 infected routers were discovered in India, Mexico, the Philippines, and Ukraine. All routers were on closed networks.
The affected models are the Cisco 1841, 2811, and 3825. Cisco has discontinued production of these router models, but FireEye researchers do not rule out the possibility that more recent models could be exploited, similarly.
