US Government Warns That Russia State Hackers Are Coming After Your Router (arstechnica.com) 76
CISA and allied governments are warning users to secure their routers as Russian state-backed hackers continue compromising the devices and turning them into proxy nodes to disguise attacks against critical infrastructure. The advisory urges users to disable outdated SNMP versions, use strong passwords, update firmware, and turn off unnecessary router services to reduce the risk of being swept into these botnets. Ars Technica reports: "Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks," the Cybersecurity and Infrastructure Security Agency said Monday. The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK.
The primary means of compromise the agency warned about was hackers scanning IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default authentication credentials. These scans are run by the very sorts of router botnets the actors are trying to enroll the targeted device in. By sending malicious traffic from spoofed addresses, the hackers can use the SNMP agent on poorly configured routers to run malware. SNMP allows users to collect and organize information about managed networking devices or to modify that information to change device behavior.
With control of a device, the hackers then use it as an exit node when probing or attacking targets in the communications, defense, energy, financial services, and government sectors. By funneling the malicious traffic through a benign-appearing device on a trustworthy IP address, the attackers are able to lower the chances of getting blocked by firewalls and other security defenses. Monday's advisory made no mention of identical operations carried out in recent years by China. So-called residential proxies are also a go-to tool used by financially motivated criminal hackers to obscure their true IP address. In many cases, these sorts of proxies are made up of millions of streaming devices that are sold with preloaded malware.
The primary means of compromise the agency warned about was hackers scanning IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default authentication credentials. These scans are run by the very sorts of router botnets the actors are trying to enroll the targeted device in. By sending malicious traffic from spoofed addresses, the hackers can use the SNMP agent on poorly configured routers to run malware. SNMP allows users to collect and organize information about managed networking devices or to modify that information to change device behavior.
With control of a device, the hackers then use it as an exit node when probing or attacking targets in the communications, defense, energy, financial services, and government sectors. By funneling the malicious traffic through a benign-appearing device on a trustworthy IP address, the attackers are able to lower the chances of getting blocked by firewalls and other security defenses. Monday's advisory made no mention of identical operations carried out in recent years by China. So-called residential proxies are also a go-to tool used by financially motivated criminal hackers to obscure their true IP address. In many cases, these sorts of proxies are made up of millions of streaming devices that are sold with preloaded malware.
standard practice (Score:3, Informative)
Aren't vulnerable routers the backbone of most botnets?
Re: (Score:2)
This is more about slipping through your firewall and getting unauthenticated snmp info, to learn more and eventually get to data. This is nothing new.
Re: (Score:2)
My bad on this one, its similar to another that is not recent.
Re: (Score:2)
Jesus Christ you are arrogant. Most people re better at their jobs than you are at yours.
Re: (Score:2)
- install OpenWRT (be sure to purchase an OpenWRT compatible router)
- configure it to DROP packets on closed ports (default is REJECT, that informs the 'hacker' that, while the port is closed, there is a device at this address)
Re:standard practice (Score:4, Interesting)
Setting the policy to DROP just means that clients will try multiple times before timing out, which means not only will you waste bandwidth with the retries, but your own clients will experience a delay while they time out instead of receiving an instant rejection.
For legacy IPv4 networks the address space is so congested and in short supply that it's economically unviable to leave unused addresses, so you gain nothing from this. With IPv6 there might be some very limited security-through-obscurity value to someone not being able to identify a live address, but its also not practical to scan sequential address space anyway.
What this article really highllghts however, is how flawed the perimeter security model is. Modern end user devices will actually do perfectly well on an open connection, as they don't have any externally visible services. Indeed people frequently connect their devices to public wifi networks where they are fully exposed to the network owner, other users and potentially beyond and it hasn't caused the apocalypse.
People are relying on the perimeter security model, and then using really lousy insecure devices to actually implement that perimeter so they get the worst possible outcome. User think their devices are inside a secured perimeter when the very device supposed to be enforcing that perimeter has been compromised putting the attacker inside. These devices are often MUCH worse than today's end user operating systems.
The proper solution is zero trust - assume your devices are fully exposed and have to stand alone.
Re: (Score:2)
Re: (Score:2)
OpenWRT only supports a handful of wifi7 routers. I can easily and readily use only two in my market (ASUS BT8 and the Beryl 7 travel router). Most consumers don't even know what is OpenWRT much less how to use it.
There are nifty little $65 routers available that would probably be "okay" if remote administration were disabled immediately on installation. OpenWRT support for these devices would make them even more-desirable. Currently the standard router for OpenWRT seems to be the Slate 2, which is an o
Re: (Score:2)
Sorry Flint 2 not Slate 2. There is no Slate 2.
Re: (Score:2)
Anyway Flint 3 / 3e is available, and Flint 4 is upcoming.
I use the Flint 2 and it's a beast + with its DDR4 1 GB / eMMC 8 GB (which is much more than most routers), any OpenWRT module can be installed.
Re: (Score:2)
Flint 3 is not supported by OpenWRT. And I have, its a wifi6 device that has benchmarked about as well as other wifi 6 devices. I can get a cheap wifi 7 unit that will push higher speeds for less money.
Re: (Score:2)
Re: standard practice (Score:1)
Re: (Score:2)
Re: (Score:2)
The article isn't about us, it's about everyone else.
Re: (Score:2)
Slashdot readers (and from other more technical sites) may take an interest in it and give it a try.
Re: (Score:2)
People need to temper their expectations regardless. The developers are doing their best, but OEMs are making it hard for them.
Re: (Score:2)
And IoT devices. Do you know who your light bulb is DoSing?
Re: (Score:2)
distract - distract - distract (Score:3, Insightful)
Re: distract - distract - distract (Score:4, Funny)
Re: distract - distract - distract (Score:5, Interesting)
Re: (Score:3, Informative)
I'm sure it was discussed during their 90 minute July 4th phone call. https://www.cnn.com/2026/07/05... [cnn.com]
Re: (Score:2)
Are those files behind such a compromisable router? That would be the day ... "Iran releases the Epstein files".
That would be funny... but also foolish. Iran is thrilled to have Trump right where he is, doing all the dumb things he's doing.
Shouldn't this be expected? (Score:3)
Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide
My only question is why the state isn't proactively identify and deactivating such devices. Seriously, if your shitty device is a threat then I see no reason that it cannot also be forcibly taken offline. People will not give a damn about security no matter how much you implore them (they haven't for decades), so it's time for the stick.
Re:Shouldn't this be expected? (Score:4, Informative)
Don't the ISPs own the wires? If so, then I would expect the state to first tell the ISP to clean up their properties. Have them show due diligence in getting their customers to update or replace (with what, from who?) their router before eventually kicking it off the network.
My last cable ISP supplied a router/modem combo that they could configure to be secure by default. For the most part, it was. It didn't have a lot of features and I didn't care for it's overall design but it did work.
My current ISP is starlink and they provide the receiver and router as well.
I imagine the vast majority of router's that are Internet/ISP facing are issued by ISPs themselves as your average user doesn't go buy their own. Even us nerds, we buy our own but depending on our ISP, it's still behind their router/modem device in the path from client to Internet.
So if ISPs are issuing the majority of devices, it would make the most sense for the state to be working with these ISP on updating the default settings and pushing out updates or otherwise helping customers update their gear. Let's hop to it people!
Re: (Score:2)
Even us nerds, we buy our own but depending on our ISP, it's still behind their router/modem device in the path from client to Internet.
In which case, the most an ISP can do if they detect an unsecured device on the customer side of their modem is to cut off service.
Lots of Windows systems will be going dark soon. Too bad you didn't upgrade when the latest OS release came down the pipe. Your new system will be available as soon as we find some DRAM.
Re: (Score:2)
Aren't the ISPs motivated to fix their shit anyway? If their customers become part of a botnet, there is a good chance that their network will get blacklisted.
Re: (Score:2)
Many simply don't care.
A lot of ISPs especially in Asia use CGNAT and/or rapidly rotating IPv6 and then do nothing about abuse so the address space is widely blacklisted.
In other countries ISPs aren't forced to use CGNAT, and use at least sticky if not fully static addressing so if customers get themselves blacklisted the ISP generally doesn't need to care as it won't affect other users.
Re: Shouldn't this be expected? (Score:2)
Re: (Score:1)
The psy-ops guys would have a field day with that. "OMG, the US government is killing your internet". It also opens up a can of worms. Next stop after that is NAC, where to be allowed onto an ISP, your router has to pass measured checks... which means no F/OSS routers, but closed source, jailbreak-proof ones... and NAC can easily turn from "checking for latest OS" to active filtering and logging with MITM SSL interception.
It's just capitalism at work. (Score:2)
Better would be to create regulation to ensure such devices receive security updates for a reasonable period of time and thereafter must be open sourced for community updates. Additionally, after such legally required support goes away or the device is otherwise in a permanently insecure state, replacing it by a secure device should be subsidized.
Even better would be to enforce that all routers must support running alternative open source firmware.
Re: (Score:2)
My question is why the state is not actively deactivating Center 16. Nuke them if we must Just get them offline. Why is Russia still attached to the internet?
fix your router, we'll trust you (Score:2)
https://www.war.gov/News/Relea... [war.gov]
Freedom to self-certify.
Re:fix your router, we'll trust you (Score:5, Funny)
Show of hands: How many people sat in on Hegseth's phone call regarding this topic?
Re: (Score:2)
Show of hands: How many people sat in on Hegseth's phone call regarding this topic?
Which call? The ones with our allies or the one with Russia?
Upgrade (Score:2)
I am glad I finally retired my older Asus router last year, even though it was running a reflash, and installed a Unifi gateway at home. They seem to be very good with updates. I even turned on the Threat Detection and Blocking (Intrusion Prevention). Then also GeoBlocking (yes, I know they can work around that, but why make it easy?) The nice thing is this little box does everything I had before and TONS more, including running cameras, with no cloud-dependencies and no recurring fees.
Alas, my contribu
Re:Upgrade (Score:4, Informative)
I am glad I finally retired my older Asus router last year, even though it was running a reflash, and installed a Unifi gateway at home. They seem to be very good with updates. I even turned on the Threat Detection and Blocking (Intrusion Prevention). Then also GeoBlocking (yes, I know they can work around that, but why make it easy?) The nice thing is this little box does everything I had before and TONS more, including running cameras, with no cloud-dependencies and no recurring fees.
Unifi has had several CVSS 10.0 vulnerabilities lately. Quite a lot of those devices are unfortunately still ending up part of botnets.
https://www.bleepingcomputer.c... [bleepingcomputer.com]
And a new one last week...
https://thehackernews.com/2026... [thehackernews.com]
Nice hardware, but the cloud services bring their own risks.
Re: (Score:3)
>"Unifi has had several CVSS 10.0 vulnerabilities lately. Quite a lot of those devices are unfortunately still ending up part of botnets. "
All platforms have vulnerabilities, unfortunately. But from what I can tell, all of those are from the inside. Not from the outside. Every one of them is "with access to the network." So these are not things that are going to give outside attackers the direct ability to break into a Unifi controller on the outside of its firewall.
Re: (Score:2)
https://www.bleepingcomputer.c... [bleepingcomputer.com]
Re: (Score:2)
There are hundreds of ways an attacker could gain access to the inside interface, even doing so blindly via xsrf where you have predictable legacy addressing.
Re: (Score:2)
They have a solid auto-updater and don't slouch when it comes to patches.
really and truly don't care (Score:1)
There are two countries I am NOT worried about and that is Russia and China, because whatever they find out about me they won't give to the USA. The USA on the other hand will abuse all the information they can get to deprive me of my liberties.
Anyway sounds like "the lady doth protest too much" to me. As a good loyal subject I'll be sure to replace my router with one with NSA-approved(R) firmware, right away, sir.
Re: (Score:2)
Re: (Score:2)
The russians have been blackmailing ukrainians in ukraine into committing acts against their own government, there are several documented cases of this.
https://www.theguardian.com/wo... [theguardian.com]
https://www.washingtonpost.com... [washingtonpost.com]
https://news.sky.com/story/how... [sky.com]
Re: (Score:2)
Re: (Score:2)
There have been numerous recently reported cases of russians gaining access to information on ordinary ukrainian citizens, and then blackmailing them to carry out spying or sabogate operations.
You absolutely do have to worry about what hostile foreign governments might do.
ISP Routers (Score:2)
So, just how are ISP customers, which are provided routers by their ISP, supposed to do this? Shouldn't it be mandated that ISPs are responsible for updating and securing routers? I realize that some ISP customers are tech saavy and wish to configure the routers themselves. For those users a simple opt-out will do. For the remaining 99.999% of users the ISP should be handling this, right?
Re: (Score:2)
For the ISP to "update and secure" my router it must be accessible from outside. That's exactly what I don't want.
Re: (Score:2)
You shouldn't be relying on perimeter security anyway, every device should be able to stand on its own in a zero trust scenario.
Re: (Score:2)
Yes, you are a tech savvy router owner. However, the other 99.999% of owners are not. This is why I believe ISPs need to be held accountable for the routers they provide their customers. There should be an area on the customer's bill showing the security status of the router as well as any updates or changes made to the router by the ISP. This would not only inform the customer of their security status but also give any tech working on your network a complete history of revisions made to the router. This sh
Learning from the best; that is us (Score:2)
We were doing this decades ago :
https://www.businessinsider.co... [businessinsider.com]
This is why I just let my ISP deal with the router (Score:1)
I don't have time to keep track of security updates for my router, apply them, and check now and then to make sure it hasn't been compromised. Comcast has the infrastructure and people to do it all themselves. I don't have to think about it at all.
Of course it's probably the only thing Comcast can do right, but I think most people on Slashdot have heard that story a million times so I won't go there!
Re: (Score:2)
Access Denied (Score:2)
That's what I get when trying to access www.cisa.gov from Firefox (currently supported ESR version). Of course it works fine in web browsers from deep-pocketed cowtowing corporate companies. Makes you wonder. Hmmm.
SNMP? (Score:3)
Any router running SNMP or a web interface configured to listen on the external (WAN) port should be considered defective and replaced (or reflashed to sane non-braindead firmware). Home networks don't need SNMP at all, and business networks not using enterprise-grade equipment probably don't need it with write enabled. The only access to the router from the WAN side should be SSH using public-key authentication, and that only if you absolutely need it (you probably don't). That solves the vast majority of problems.
Re: (Score:2)
Home networks do need SNMP. How else would you know that your network printer is running low in ink?
A lot of home automation equipment also uses SNMP, although MQTT has become more popular in recent years.
The router not having ports of its own open on the internet side seems reasonable, but ISPs want to be able to remotely configure their modem routers at their customers.
The best way to hijack a router is from the internal side anyway. JavaScript in web ads can do wonders.
Attack of the commie cyber bogeyman :o (Score:2)
Well maybe (Score:2)
Trump Putin "agreement" (Score:2)
passwordless? (Score:2)
so is the US government (Score:1)
the hypocrisy...
What's the Real Danger? (Score:2)
This has got to be a REALLY small attack surface, right? I mean, first we have to exclude all the routers behind CGNAT since there should be no way to get to the SNMP port unless the carrier is doing a port forward for SNMP... which would be super weird. Then exclude 90% of all consumer-grade routers because most of them don't have SNMP capability or don't have it enabled, and even if so then it'd have to be a really idiotically set up router to not have that isolated only to internal network interfaces or
Re: (Score:2)
Assuming that CGNAT makes you immune is a huge error.
Once you compromise a single customer you're now inside the CGNAT pool, where you will see lots of very vulnerable devices because they were left vulnerable on the assumption that they were not reachable. In an ISP with thousands of customers, at least a handful will have some infected devices.
Modern Windows devices absolutely do not become compromised via inbound connections to open ports, they become compromised via vulnerable client software or user er
They banned "Chinese" routers ...meanwhile (Score:2)
The routers found with the issues so far...drum-roll...."mainly Cisco and Netgear devices that had reached their end of life"....
Meanwhile Netgear was the first company to clear the ban?...... Netgear says: Welcome to your requested the backdoor NSA ... ;P
Good Advice (Score:2)