Tens of thousands of MikroTik and Ubiquiti routers are currently available online, featuring alarmistic hostnames such as "HACKED FTP server," "HACKED-ROUTER-HELP-SOS-WAS-MFWORM-INFECTED," or "HACKED-ROUTER-HELP-SOS-HAD-DEFAULT-PASSWORD."
In reality, these devices have not been hacked, just defaced, and appear to be the subject of some prank of vigilante's actions.
Attackers aren't taking over devices, but merely changing the devices' names (hostnames), as a warning for device owners, hoping that users will take action and secure their routers.
Defacements started in 2017 with Ubiquiti devices
Spotted by
Ankit Anubhav, Principal Researcher at NewSky Security, a cyber-security company specialized in IoT security, these benign hacks have been going on since last summer.
Speaking to
Bleeping Computer, Anubhav says he first spotted these defacements
last July, when he found over 36,000 Ubiquiti routers with strange hostnames [
1,
2,
3], a number that has grown to over 40,000.
The hostnames of the defaced Ubiquiti routers are the same ones used in a
2016 campaign when hackers changed Ubiquiti router logins to username "mother" and password "#####er".
Last year's and the recent Ubiquiti defacements don't appear to change the user's password like in the 2016 campaign, but only the router's hostname.