Cyber Attacks

Thousands of routers exposed to Eternal Silence attacks via UPnP

0

A hacking campaign, tracked as Eternal Silence, is abusing Universal Plug and Play (UPnP) to compromise routers and use them to carry out malicious activities.

The researchers from Akamai have spotted this malicious campaign which abuses UPnP to turn routers into a proxy server used to carry out malicious activities anonymously.

Universal Plug and Play (UPnP) is a set of networking protocols that allows networked devices to seamlessly discover each other’s presence on the network and establish functional network services.

Researchers from Akamai spotted that out of 3,500,000 UPnP routers found online, 277,000 are vulnerable to UPnProxy, and 45,113 of them have already been infected by hackers.

Akamai’s analysts speculate that the actors attempt to exploit EternalBlue (CVE-2017-0144) and EternalRed (CVE-2017-7494) on unpatched Windows and Linux systems, respectively.

Leveraging these flaws can lead to an array of potential problems, including resource-consuming cryptominer infections, devastating worm-like attacks that quickly spread to entire corporate networks, or initial access to corporate networks.

The new rulesets defined by the hackers contain the phrase ‘galleta silenciosa’, which is Spanish for ‘silent cookie’.

The injections attempt to expose TCP ports 139 and 445 on devices connected to the targeted router, roughly 1,700,000 machines running SMB services.

‘Eternal Silence’ is a very cunning attack because it renders the practice of network segmentation ineffective and doesn’t give any indication of what is happening to the victim.

The best way to determine if your devices have been captured is by scanning all endpoints and auditing the NAT table entries.

If you have located a device compromised with Eternal Silence, disabling UPnP won’t clear the existing NAT injections. Instead, users will need to reset or flash the device.

Also, you must update latest firmware as the device vendor may have addressed any UPnP implementation flaws via a security update.

Image Credit : Security Boulevard

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

State-sponsored Iranian hackers attack Turkish government, private organizations

Previous article

Dozens of UEFI flaws impact millions of devices used by major vendors

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *