Compromised Routers: Tool of Choice for Crime & Espionage
ID: 79b39ebf-68f5-5681-8747-f1a45fbe37ff
STIX ID: report--79b39ebf-68f5-5681-8747-f1a45fbe37ff
Feed Name: securityonline.info
TrendMicro reports widespread compromise of routers (notably Ubiquiti EdgeRouter) that have been abused since at least 2016 by cybercriminal botnets and the APT group Pawn Storm to provide anonymization/proxy infrastructure for espionage, spamming, SSH brute forcing, Monero mining, and commercial proxy services (Ngioweb); an FBI disruption in January 2024 modified many devices but did not fully eliminate the threat, and operators have rebuilt C2s and expanded to other devices. The report recommends firmware updates, changing default credentials, monitoring network traffic, and tracking specific IOCs to detect and mitigate these abuses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
