Have Russian hackers used a router exploit to break into your business?

Russian hackers have reportedly managed to gain access to more than 18,000 business networks by exploiting a flaw in older internet routers.

The attack was perpetrated by a Russia-backed firm known as Forest Blizzard (also known as APT28 and Fancy Bear). It managed to steal authentication tokens from thousands of users without using any malicious code or phishing attacks.

Compromised routers

The attack focused on one of the internet’s notorious weak links: the DNS addressing system.

The Russian hackers targeted vulnerable routers that are largely used in a SOHO environment, from manufacturers such as TP-Link and MikroTik. The UK’s National Cyber Security Centre website has a list of affected routers if you want to check whether your company’s device is on the list.

Once the hacking group had gained access to the router, they changed its DNS settings to redirect select internet traffic via a virtual server controlled by the hackers. Notably, they didn’t reroute all internet traffic. Most traffic on the exploited routers resolved as normal, helping the attackers to avoid detection. Instead, they focused on rerouting high-value domains such as Outlook.com.

Crucially, the attackers were able to propagate the malicious DNS settings to all users on the local network, where victims were silently rerouted to adversary-in-the-middle (AiTM) nodes.

The attackers didn’t have to do anything as suspect as rerouting victims to fake login pages, hoping they would re-enter usernames and passwords. Instead, they collected OAuth authentication tokens transmitted by victims.

OAuth tokens are granted after you’ve already logged in and passed through any two-factor authentication process. By stealing those tokens the hackers are able to access systems as if they’re the user themselves.

“Most victims were associated with third-party IT, hosting and smaller cloud service providers in Europe,” a post by the security firm Lumen claims.

“We also identified connections to various email services providers, both in the US and across Europe. These connections indicate that individual accounts were compromised rather than any systemic compromise of the backend systems.”

How to recover from Russian hacker attack

Lumen’s post includes a number of steps that companies can take if they suspect they may have been a victim of the attack, including “certificate pinning”, which would prevent access to the attackers’ virtual servers, and removing end-of-life equipment from networks (the routers targeted were largely older units, no longer receiving security updates).

TP-Link was among a slew of foreign router manufacturers who were recently banned from selling consumer routers in the US, purportedly because of concerns over security.

Avatar photo
Barry Collins

Barry has 25 years of experience working on national newspapers, websites and magazines. He was editor of PC Pro and is co-editor and co-owner of BigTechQuestion.com. He has published a number of articles on TechFinitive covering data, innovation and cybersecurity.