logo

Podcast Episode 116: Cryptojacking and MikroTik’s Bad-Feeling Feel Good Patch Story

ID: a2364aa1-3206-5bfe-9685-37aa3a5d634e

STIX ID: report--a2364aa1-3206-5bfe-9685-37aa3a5d634e

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2018-10-15

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

The report describes widespread, active exploitation of unpatched MikroTik RouterOS devices to run cryptojacking malware by injecting mining code via modified proxy services; despite patches released months earlier, many carriers and operators failed to update devices, leaving hundreds of thousands of routers exposed. The piece also notes that threat actors including the APT 'FancyBear' have targeted MikroTik devices (using default credentials and other flaws) to deploy malware such as VPNFilter, underlining systemic risks from unpatched infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.