Researchers Claim 400,000+ MikroTik Routers Infected With Mining Malware

- Advertisement -

December 7, 2018 12:36 AM

MikroTik mining malware was first discovered in Brazil in August, but the virus continues to spread all over the world.

Malware that specifically targets MikroTik routers could now be affecting more than 415,000 routers across the globe, according to a December 2 tweet from VriesHD.

The malware, which typically uses software to secretly mine Monero, was first discovered in Brazil in August.

- Advertisement -

According to Bad Packets LLC, a security research firm, over 170,000 routers in Brazil were infected with the mining malware. Security researcher Simon Kenin of cybersecurity firm Trustwave described the attack by saying:

“The attacker wisely thought that instead of infecting small sites with few visitors or finding sophisticated ways to run malware on end-user computers, they would go straight to the source: carrier-grade router devices.”

According to Bad Packets, the epidemic is spreading – by August 25, those infected included approximately 3,000 MikroTik routers in the US containing IP addresses assigned to internet service provider Cogent. A month later, over 600 routers belonging to the Douglas County Public Utility District in north-central Washington state were infected with the malware. According to Bad Packets, “39% of the IPs they manage route to a compromised device.”

While research shows that Coinhive is used in most of these instances, during the largest “campaign” CoinImp software was used to infect 115,000 routers. And in September, Bad Packets pointed out more malware targeting MikroTik routers, this one injecting MinerAlt software, which is also used to mine Monero, to steal 30 percent of users’ mining revenue. To avoid detection, “Infected routers in this campaign are configured to throttle the CPU usage of the victims’ devices… the amount of CPU power used for mining cryptocurrency is roughly 80%.”

Although those responsible for the malware cleverly evolve their methods to circumvent discovery, there is at least one patch victims, internet services providers, and MikroTik router owners can use to protect themselves. And it was actually released way back in April. MikroTik’s patch, which intended to “fix a zero-day vulnerability exploited in the wild,” was released after users of a Czech tech forum spotted malware mining attacks targeting a remote management service called Winbox, which is included with all MikroTik routers. The service allows users to configure devices.

However, even after multiple warnings to upgrade routers – from MikroTik and security researchers, a large number of devices could still be infected. According to a September tweet from Bad Packets, several hundred thousand hosts were still compromised. 

Describing the challenge of upgrading one’s router, a researcher from VriesHD told Hard Fork:

“Users should indeed update their routers, yet the biggest bunch of them are distributed by ISPs to their customers, who often have no idea what to do or how to update the router. Often these distributed routers are limited in their rights as well, not allowing users to update the routers themselves. The patch for this specific problem has been out for months and I’ve seen ISPs with thousands of infections disappear from the list. Unfortunately, it appears tons of ISPs simply won’t take action to mitigate the attacks.”

Nathan Graham is a full-time staff writer for ETHNews. He lives in Sparks, Nevada, with his wife, Beth, and dog, Kyia. Nathan has a passion for new technology, grant writing, and short stories. He spends his time rafting the American River, playing video games, and writing.

Like what you read? Follow us on X @Bitnewsbot to receive the latest MikroTik, Monero or other Ethereum technology news.



Previous Articles:

- Advertisement -

Latest News

Nvidia rallies on China comeback; Wall Street eyes $300 soon

NVIDIA plans to raise H200 chip production to meet strong demand from China.President Donald...

Aave CEO Urges RWA Push After Governance Vote Rejection Now.

Stani Kulechov outlined a wider strategy after a governance vote rejected a proposal to...

SEC Commissioner Caroline Crenshaw Resigns; Crypto Win Ahead

Caroline Crenshaw has resigned from the Securities and Exchange Commission, announced in a Friday...

CryptoQuant: Whale ‘Reaccumulation’ Narrative Overstated Now

Onchain data from CryptoQuant indicate claims of large-scale Bitcoin reaccumulation by whales are overstated.Exchange...

XRP Eyes Rally as ETFs and Buy Signal Boost 2026 Hopes Surge

Ripple settled its US lawsuit in 2025, helping XRP reach a $3.65 all-time high...
- Advertisement -

Must Read

7 Best Crypto To Invest In This Year

Investing in cryptocurrencies has become a popular way for people to diversify their investment portfolio and make potential profits.However, with so many cryptocurrencies available...
Bitcoin (BTC) $ 90,213.00 1.58%
Ethereum (ETH) $ 3,123.25 3.73%
XRP (XRP) $ 2.02 7.53%
Bittensor (TAO) $ 253.01 6.62%
Polkadot (DOT) $ 2.15 7.69%
Cardano (ADA) $ 0.395211 9.95%
Chainlink (LINK) $ 13.25 4.18%
Hyperliquid (HYPE) $ 24.47 0.61%
Monero (XMR) $ 425.97 2.34%
Hedera (HBAR) $ 0.121225 6.07%
Toncoin (TON) $ 1.83 9.27%