🔮 Better than the Oracle? Our Fair Value found this +42% bagger 5 months before Buffett bought itRead More

Cisco router break-ins bypass cyber defenses

Published 09/16/2015, 03:59 AM
© Reuters. The Cisco Systems logo is seen as part of a display at the Microsoft Ignite technology conference in Chicago
CSCO
-
MNDT
-

By Eric Auchard

FRANKFURT (Reuters) - (Company corrects the 15th paragraph beginning "The malicious programme..." to clarify that the nickname SYNful refers to the signal routers sent to open up communication with other routers, rather than how the implanted software jumps between routers.)

Security researchers say they have uncovered clandestine attacks across three continents on the routers that direct traffic around the Internet, potentially allowing suspected cyberspies to harvest vast amounts of data while going undetected.

In the attacks, a highly sophisticated form of malicious software, dubbed SYNful Knock, has been implanted in routers made by Cisco, the world's top supplier, U.S. security research firm FireEye said on Tuesday.

Routers are attractive to hackers because they operate outside the perimeter of firewalls, anti-virus, behavioral detection software and other security tools that organizations use to safeguard data traffic. Until now, they were considered vulnerable to sustained denial-of-service attacks using barrages of millions of packets of data, but not outright takeover.

"If you own (seize control of) the router, you own the data of all the companies and government organizations that sit behind that router," FireEye Chief Executive Dave DeWalt told Reuters of his company's discovery.

"This is the ultimate spying tool, the ultimate corporate espionage tool, the ultimate cybercrime tool," DeWalt said.

The attacks have hit multiple industries and government agencies, he said.

Cisco confirmed it had alerted customers to the attacks in August and said they were not due to any vulnerability in its own software. Instead, the attackers stole valid network administration credentials from targeted organizations or managed to gain for themselves physical access to the routers.

"We've shared guidance on how customers can harden their network, and prevent, detect and remediate this type of attack," Cisco said in a statement.

CYBERSPIES SEEN RESPONSIBLE

Altogether FireEye's computer forensic arm Mandiant has so far found 14 instances of the router implants in India, Mexico, Philippines and Ukraine, the company said in a blog post at http://bit.ly/1ObMm7u. It added that this may be just the tip of the iceberg in terms of yet-to-be-discovered attacks.

Because the attacks actually replace the basic software controlling the routers, infections persist when devices are shut off and restarted. If found to be infected, FireEye said basic software used to control those routers would have to be re-imaged, a time-consuming task for technicians.

Hitherto, infections of commercial routers, while not unknown, have largely remained theoretical threats, DeWalt said, as distinct from routers consumers use at home, which according to media reports have been hit by malware in recent years.

Experts reckon there are only a small number of nations with cyber intelligence services which are capable of such attacks on network equipment, including those of Britain, China, Israel, Russia and the United States.

"That feat is only able to be obtained by a handful of nation-state actors," DeWalt said, while declining to name which countries he suspected might be behind the Cisco router attacks.

The malicious program has been nicknamed "SYNful," a reference to SYN, the signal a router sends when it starts to communicate with another router, a process which the implant exploited, according to FireEye.

Network logs from infected routers suggest the attacks have been taking place for at least a year, FireEye's CEO said.

The implanted software, which duplicates normal router functions, could also potentially affect routers from other makers, DeWalt said.

Infected hardware devices include Cisco routers 1841, 2811 and 3825, FireEye said. Cisco had discontinued selling the products but still supports customers using them.

© Reuters. The Cisco Systems logo is seen as part of a display at the Microsoft Ignite technology conference in Chicago

FireEye said it was only announcing its discovery after working with Cisco to quietly notify governments and affected parties. "We thought it was best to release this so everyone can fix their routers as fast as possible," DeWalt said.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.