D-Link routers under siege from months-long DNS hack

The attackers are running malicious IPs through a Google Cloud Platform virtual machine

Picture of a DNS server

An ongoing hacking campaign is targeting consumer network routers, mainly D-Link branded ones, which hijacks DNS traffic redirecting users away from legitimate sites and towards malicious clones.

The attackers made attempts on vulnerable router firmware using a Google Cloud Shell which, according to Troy Mursch, a security researcher at Bad Packets, who discovered the issue, is notoriously easy to abuse. 

Advertisement - Article continues below

"Anyone with a Google account can access a 'Google Cloud Shell' machine by simply visiting [the Cloud Shell URL]. This service provides users with the equivalent of a Linux VPS with root privileges directly in a web browser," said Murshc. "Due to the ephemeral nature of these virtual machines coupled with Google's slow response time to abuse reports, it's difficult to prevent this kind of malicious behavior."

Mursch said he found three waves of these attacks dating back to December 2018, tweeting about them as and when they were discovered. IT Pro has contacted D-Link for its side of the story but has not immediately replied.

The attack works by injecting the IP addresses (four have been used so far) of rogue DNS servers inside the vulnerable routers. The servers changed the IP addresses of legitimate sites to malicious copies the attackers were running. The attack is still running at present.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

It points to a sophisticated phishing attack where unsuspecting users would visit the seemingly legitimate site and input their real login credentials ready to be intercepted by attackers.

The attack should be heeded by consumers and businesses alike because although only consumer home routers are affected, remote working culture is on the up and SMBs are also known to rely on home network packages and routers as enterprise offerings are too costly and provide more service than required.

There was a fairly high-profile example of this happening back in October 2018 where Brazillian banks were targeted via DNS hijackers, again harnessing three-year-old exploits in D-Link routers, according to Radware researchers.

The leader of an Estonian cybercrime group was charged in 2018 after pleading guilty to the distribution of malware called DNSChanger. Once infected, the malware would change the DNS settings on infected computers (Windows and Mac versions were about), replacing legitimate ads on websites with ads that would reward the man's own company Rove Digital.

Advertisement - Article continues below

Between 2007 and 2011, the company lead by Vladimir Tsastsin, 35, and six other men raked in $14 million through click hijacking and ad-replacement fraud.

The group were originally arrested in 2011 and later acquitted until 2014 where the Estonian Supreme Court revoked their acquittal and charged them for money laundering.

Advertisement

Recommended

Visit/security/cyber-security/355185/165-million-britons-experienced-a-cyber-crime-in-the-past-year
cyber security

Report: 16.5 million Britons fell victim to cyber crime in the past year

1 Apr 2020
Visit/cloud/amazon-web-services-aws/355183/aws-launches-amazon-detective
Amazon Web Services (AWS)

AWS launches Amazon Detective for investigating security incidents

1 Apr 2020
Visit/security/privacy/355182/government-to-launch-coronavirus-contact-tracking-app
privacy

UK government to launch coronavirus 'contact tracking' app

1 Apr 2020
Visit/software/video-conferencing/355180/zoom-does-not-use-end-to-end-encrypted
video conferencing

Zoom admits meetings don't use end-to-end encryption

1 Apr 2020

Most Popular

Visit/development/application-programming-interface-api/355192/apple-buys-dark-sky-weather-app-and-leaves
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
Visit/security/cyber-crime/355171/fbi-warns-of-zoom-bombing-hackers-amidst-coronavirus-usage-spike
cyber crime

FBI warns of ‘Zoom-bombing’ hackers amid coronavirus usage spike

31 Mar 2020
Visit/data-insights/data-management/355170/oracle-cloud-courses-are-free-during-coronavirus-lockdown
data management

Oracle cloud courses are free during coronavirus lockdown

31 Mar 2020