Security News The US government warns that Russia state hackers are coming after your router

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors.

Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers. Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones.

Proxy networks: The go-to tool
Full Story:
 
Full Story:
The risk is real, but home users do not need to panic. Routers are attractive targets because they often remain online, receive fewer security updates than computers, and can be used to hide later activity.

Recommended steps for home and small-office routers

  • Check the manufacturer’s support page for the exact model and install the latest firmware. Enable automatic updates if the router supports them.
  • Replace the router if it is end-of-life, no longer receives security updates, or has an unknown firmware status.
  • Change the router’s administrator username and password, and do not reuse that password elsewhere.
  • Disable remote administration from the Internet unless it is specifically required. If it is necessary, restrict access by VPN or an allowlist.
  • Disable UPnP, WPS, and unused services when they are not needed.
  • Use WPA2-AES or WPA3 for Wi-Fi, with a long unique Wi-Fi password. Avoid WEP and outdated WPA/TKIP modes.
  • Review connected-device and DNS settings for anything unfamiliar. Unexpected DNS servers, administrator accounts, port forwards, or configuration changes deserve attention.
  • Use a separate guest network for visitors and less-trusted IoT devices.
  • Back up the configuration only if the backup can be stored securely; do not restore an old configuration after a suspected compromise without reviewing it.

A reboot alone is not a reliable cleanup measure. If compromise is suspected, save relevant logs if available, perform a factory reset using the manufacturer’s documented procedure, update the firmware, and manually reconfigure the device. Contact the ISP or router manufacturer if the settings repeatedly change or the device behaves abnormally.

The linked article may contain details that cannot be verified from the excerpt alone, so its specific claims should be checked against the relevant government advisory and the router manufacturer’s security notices. The practical takeaway remains the same: keep the firmware current, remove Internet exposure that is not needed, and replace unsupported equipment.
 
Anthropic Claude AI says OPNsense and Mikrotik issues almost monthly patches. I have a MikroTik and can attest to this monthly patching.

Bot did not read the article. The article says to upgrade to SNMP v3 or disable it.

Secure your router, we all have to do our part.
 
Last edited:
The primary means of compromise the agency warned about was hackers scanning IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default authentication credentials. These scans are run by the very sorts of router botnets the actors are trying to enroll the targeted device in. By sending malicious traffic from spoofed addresses, the hackers can use the SNMP agent on poorly configured routers to run malware. SNMP allows users to collect and organize information about managed networking devices or to modify that information to change device behavior.

With control of a device, the hackers then use it as an exit node when probing or attacking targets in the communications, defense, energy, financial services, and government sectors. By funneling the malicious traffic through a benign-appearing device on a trustworthy IP address, the attackers are able to lower the chances of getting blocked by firewalls and other security defenses.

Monday’s advisory made no mention of identical operations carried out in recent years by China. So-called residential proxies are also a go-to tool used by financially motivated criminal hackers to obscure their true IP address. In many cases, these sorts of proxies are made up of millions of streaming devices that are sold with preloaded malware.

The agency urged router users to lock down their devices. Chief among the suggestions is to ensure SNMP versions 1 and 2 are disabled, because they don’t encrypt passwords or follow other common-sense security practices. Instead, only SNMP version 3 should be used. A better option is to disable SNMP altogether unless it’s needed for a specific use. Other safeguards include disabling Cisco Smart Install on all devices, using strong passwords, updating firmware regularly, and avoiding the use of other networking protocols.
 
Full Story:
Well if the GOV has proven anything between January 20 2021 and January 20 2025, it is that it can't be believed. And since that is the case, for my PC protection from such nefarious actions, and activities, can I have Kaspersky back, that is probably the best protection from those who are the real threat.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top