Cyclops Blink malware sets up shop in ASUS routers
- Reference: 1647630160
- News link: https://www.theregister.co.uk/2022/03/18/cyclops_asus_routers/
- Source link:
ASUS says it's [1]working on a remediation for Cyclops Blink and will post software updates if necessary. The hardware maker recommends users reset their gateways to factory settings to flush away any configurations added by an intruder, change the login password, make sure remote management access from the WAN is disabled, and ensure the latest firmware is installed to be safe.
Cyclops Blink has ties to Kremlin-backed Sandworm, the criminal gang behind the nasty [2]VPNFilter malware that in 2018 targeted routers and storage devices. The crew also carried out several high-profile attacks including the 2015 and 2016 cyber-assaults on Ukraine's electrical grid, NotPetya in 2017, and the French presidential campaign email leak that same year.
[3]
A Trend Micro [4]warning about the router hijackings follows a [5]joint advisory last month from the FBI, CISA, the US Department of Justice, and the UK National Cyber Security Centre about Cyclops Blink, which the agencies said looked to be Sandworm's replacement for VPNFilter. At the time, the botnet had its sights set on [6]WatchGuard firewall appliances.
[7]
"Our data also shows that although Cyclops Blink is a state-sponsored botnet, its C&C servers and bots affect WatchGuard Firebox and Asus devices that do not belong to critical organizations, or those that have an evident value on economic, political, or military espionage," Trend Micro said. "Hence, we believe that it is possible that the Cyclops Blink botnet's main purpose is to build an infrastructure for further attacks on high-value targets."
And while Cyclops Blink has infected routers from these two hardware providers, "we have evidence that the routers of at least one vendor other than Asus and WatchGuard are connecting to Cyclops Blink C&Cs as well, but so far we have been unable to collect malware samples for this router brand," the security shop said.
[8]Ukraine hit by DDoS attacks, Russia deploys malware
[9]France's cyber-agency says Centreon IT management software sabotaged by Russian Sandworm
[10]Ukraine invasion: This may be the quiet before the cyber-storm, IT staff warned
[11]Where are the (serious) Russian cyberattacks?
It's not clear exactly right now how the malware gets onto a device, though it probably involves exploiting a default admin password to gain access via an enabled remote management service. According to Trend Micro's Cyclops Blink technical analysis, once the modular malware, written in C, has been injected into the gateway and is running, it sets itself up and renames its process to "[ktest]" presumably to appear as a Linux kernel thread.
Next, it waits for 37 seconds and decides on the hard-coded command-and-control (C2) server to talk to along with the rate at which it communicates with the box. Then it begins communicating with its C2 server using an OpenSSL-encrypted channel to join the Cyclops Blink botnet. Among the commands it can receive, the compromised router can be given more malware to run, allowing the botnet's controllers to do whatever they like on the hijacked gateways. ®
Get our [12]Tech Resources
[1] https://www.asus.com/content/ASUS-Product-Security-Advisory/
[2] https://www.theregister.com/2018/09/27/fancy_bear_modules/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjUPIHdRm6F3wjBdPmFoLwAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html
[5] https://www.cisa.gov/uscert/ncas/current-activity/2022/02/23/new-sandworm-malware-cyclops-blink-replaces-vpnfilter
[6] https://www.watchguard.com/wgrd-news/blog/important-detection-and-remediation-actions-cyclops-blink-state-sponsored-botnet
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjUPIHdRm6F3wjBdPmFoLwAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/02/23/ukraine_ddos_russia_malware/
[9] https://www.theregister.com/2021/02/16/centreon_sandworm_attack/
[10] https://www.theregister.com/2022/03/09/ukraine_russia_cyberattacks/
[11] https://www.theregister.com/2022/03/09/where_are_the_russian_cyberattacks/
[12] https://whitepapers.theregister.com/
Makes you wonder
"The hardware maker recommends users reset their gateways to factory settings to flush away any configurations added by an intruder, change the login password, make sure remote management access from the WAN is disabled"
ASUS produces consumer electronics. Why would their plastic routers even have an option for WAN management?
Also, I remember Buffalo routers (consumer tat as well) having a unique, factory-set password for the admin user. This was in the 00s. Why can't all manufacturers do this?
FreshTomato and all those WRT firmware projects have immensely better UI, set of features and maintained code than the firmware made by the in-house coders. The manufacturers should fire them all and license one of those 3rd parties to produce a branded firmware.
Eejit guide to detection...?
I wonder if there is a simple way to discover whether one of these routers is infected? I expect a lot of these appliances sit in low-IT-capability homes and doing a factory reset "just in case" will put off most home users.
The joy of hardware attacks
Let's hope all those owners of Asus routers get the message eh ;)
... a quick web search reveals none of the big news vendors have picked up on this yet, just some niche technology sites