logo

Another year, another wave of home router hacks

ID: ac5655dc-13fc-548c-aae8-9aa142dba513

STIX ID: report--ac5655dc-13fc-548c-aae8-9aa142dba513

Feed Name: CERT Polska

Threat Score
65/100

Date Published: 2015-03-11

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT.PL reports an active criminal campaign that compromises home routers by brute-forcing administrative interfaces and changing DHCP DNS settings to attacker-controlled servers. The malicious DNS redirects users of Internet banking to an attacker proxy that downgrades HTTPS to HTTP to intercept credentials, while attacker traffic to banks is routed through other hacked routers to appear as normal consumer traffic; observed malicious DNS servers include 188.132.242.156 and 94.242.202.187. Recommended mitigation: disable WAN access to the router’s admin web panel and report occurrences.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.