News: 1647630160

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cyclops Blink malware sets up shop in ASUS routers

(2022/03/18)


Cyclops Blink malware has infected ASUS routers in what Trend Micro says looks like an attempt to turn these compromised devices into command-and-control servers for future attacks.

ASUS says it's [1]working on a remediation for Cyclops Blink and will post software updates if necessary. The hardware maker recommends users reset their gateways to factory settings to flush away any configurations added by an intruder, change the login password, make sure remote management access from the WAN is disabled, and ensure the latest firmware is installed to be safe.

Cyclops Blink has ties to Kremlin-backed Sandworm, the criminal gang behind the nasty [2]VPNFilter malware that in 2018 targeted routers and storage devices. The crew also carried out several high-profile attacks including the 2015 and 2016 cyber-assaults on Ukraine's electrical grid, NotPetya in 2017, and the French presidential campaign email leak that same year.

[3]

A Trend Micro [4]warning about the router hijackings follows a [5]joint advisory last month from the FBI, CISA, the US Department of Justice, and the UK National Cyber Security Centre about Cyclops Blink, which the agencies said looked to be Sandworm's replacement for VPNFilter. At the time, the botnet had its sights set on [6]WatchGuard firewall appliances.

[7]

"Our data also shows that although Cyclops Blink is a state-sponsored botnet, its C&C servers and bots affect WatchGuard Firebox and Asus devices that do not belong to critical organizations, or those that have an evident value on economic, political, or military espionage," Trend Micro said. "Hence, we believe that it is possible that the Cyclops Blink botnet's main purpose is to build an infrastructure for further attacks on high-value targets."

And while Cyclops Blink has infected routers from these two hardware providers, "we have evidence that the routers of at least one vendor other than Asus and WatchGuard are connecting to Cyclops Blink C&Cs as well, but so far we have been unable to collect malware samples for this router brand," the security shop said.

[8]Ukraine hit by DDoS attacks, Russia deploys malware

[9]France's cyber-agency says Centreon IT management software sabotaged by Russian Sandworm

[10]Ukraine invasion: This may be the quiet before the cyber-storm, IT staff warned

[11]Where are the (serious) Russian cyberattacks?

It's not clear exactly right now how the malware gets onto a device, though it probably involves exploiting a default admin password to gain access via an enabled remote management service. According to Trend Micro's Cyclops Blink technical analysis, once the modular malware, written in C, has been injected into the gateway and is running, it sets itself up and renames its process to "[ktest]" presumably to appear as a Linux kernel thread.

Next, it waits for 37 seconds and decides on the hard-coded command-and-control (C2) server to talk to along with the rate at which it communicates with the box. Then it begins communicating with its C2 server using an OpenSSL-encrypted channel to join the Cyclops Blink botnet. Among the commands it can receive, the compromised router can be given more malware to run, allowing the botnet's controllers to do whatever they like on the hijacked gateways. ®

Get our [12]Tech Resources



[1] https://www.asus.com/content/ASUS-Product-Security-Advisory/

[2] https://www.theregister.com/2018/09/27/fancy_bear_modules/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjUPIHdRm6F3wjBdPmFoLwAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html

[5] https://www.cisa.gov/uscert/ncas/current-activity/2022/02/23/new-sandworm-malware-cyclops-blink-replaces-vpnfilter

[6] https://www.watchguard.com/wgrd-news/blog/important-detection-and-remediation-actions-cyclops-blink-state-sponsored-botnet

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjUPIHdRm6F3wjBdPmFoLwAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/02/23/ukraine_ddos_russia_malware/

[9] https://www.theregister.com/2021/02/16/centreon_sandworm_attack/

[10] https://www.theregister.com/2022/03/09/ukraine_russia_cyberattacks/

[11] https://www.theregister.com/2022/03/09/where_are_the_russian_cyberattacks/

[12] https://whitepapers.theregister.com/



The joy of hardware attacks

HAL-9000

Let's hope all those owners of Asus routers get the message eh ;)

... a quick web search reveals none of the big news vendors have picked up on this yet, just some niche technology sites

Makes you wonder

Sandtitz

"The hardware maker recommends users reset their gateways to factory settings to flush away any configurations added by an intruder, change the login password, make sure remote management access from the WAN is disabled"

ASUS produces consumer electronics. Why would their plastic routers even have an option for WAN management?

Also, I remember Buffalo routers (consumer tat as well) having a unique, factory-set password for the admin user. This was in the 00s. Why can't all manufacturers do this?

FreshTomato and all those WRT firmware projects have immensely better UI, set of features and maintained code than the firmware made by the in-house coders. The manufacturers should fire them all and license one of those 3rd parties to produce a branded firmware.

Eejit guide to detection...?

sorry, what?

I wonder if there is a simple way to discover whether one of these routers is infected? I expect a lot of these appliances sit in low-IT-capability homes and doing a factory reset "just in case" will put off most home users.

History shows that the human mind, fed by constant accessions of knowledge,
periodically grows too large for its theoretical coverings, and bursts
them asunder to appear in new habiliments, as the feeding and growing
grub, at intervals, casts its too narrow skin and assumes another...
Truly the imago state of Man seems to be terribly distant, but every
moult is a step gained.
-- Charles Darwin, from "Origin of the Species"