Cybercriminals launch attacks on home routers via Google Cloud Platform
Cybercriminals have taken advantage of Google’s cloud service to target several consumer routers to redirect DNS queries from legitimate sites to malicious ones.
According to security researcher Troy Mursch at Bad Packets, the attack is easy to carry out.
He said that anyone with a Google account can access a 'Google Cloud Shell' machine by simply visiting the Google Cloud console.
"This service provides users with the equivalent of a Linux VPS with root privileges directly in a web browser," he said. "Due to the ephemeral nature of these virtual machines coupled with Google’s slow response time to abuse reports, it’s difficult to prevent this kind of malicious behaviour."
There have been three waves of attacks since December last year. In all three waves, a reconnaissance scan was carried out using Masscan to check for active hosts on port 81/tcp prior to attempting the DNS hijacking exploits. The attacks targeted D-Link DSL-2640B, D-Link DSL-2740R, D-Link DSL-2780B and D-Link DSL-526B routers.
The hack intended to modify DNS settings in the routers to point to unauthorised webpages that scan user data.
The latest wave of attacks came from three distinct Google Cloud Platform hosts and targeted additional types of consumer routers not previously seen before including: ARG-W4 ADSL routers, DSLink 260E routers, Secutech routers, and TOTOLINK routers, according to Mursch.
"The rogue DNS servers used in this round, 184.108.40.206 and 220.127.116.11, are both hosted in Russia by Inoventica Services. Internet access is provided by their subsidiary Garant-Park-Internet Ltd (AS47196)," he added.
Mursch said that users should keep their home router firmware up-to-date.
"When security vulnerabilities are discovered, they are usually patched by the manufacturer to mitigate further attacks. It’s also advisable to review your router’s DNS settings to ensure they haven’t been tampered with," he added.
Mihai Vasilescu, security researcher at Ixia, told SC Media UK that for end users, simple precautions can mitigate many of the risks we face online.
"Making sure that our devices—in this case routers—are up-to-date and not exposing the admin interface online is important," he said.
"Also, be extra careful when accessing important websites, banking especially. Make sure that the connections are HTTPS, check the certificate. All of this is important to make sure that when you're entering your credentials, they don't get to someone else."
In a blog post, he added that hackers have also targeted Netflix, PayPal, Uber, Gmail, and others in phishing attacks.
Eoin Keary, CEO and co-founder of Edgescan, told SC Media UK that one of the prime factors to successful compromise is having the router Administration console exposed to the public Internet.
"Most routers can enable "Loopback only" so only local connections can connect to the router administration console. In addition, such attacks are a good reason to ensure default credentials and weak passwords are not used on consumer routers. In fairness, many router vendors now provide the hardware with complex credentials and secure defaults, but older routers are significantly more vulnerable and have few if no security controls enabled by default," he said.
- Outside IR35 Contract- SC / DV - Cloud / VMware Solution Architect
- Outside IR35
Solution Architect Contract - with active Security Clearance needed for Outside IR35 Contract London. SC / DV (must be willing to undergo DV) 6 month rolling Immediate Experience delivering technical Security Architecture design / assurance of security design. Specific experience with Cloud and VMWARE technologies Cross domain experience desirable HLD / LLD Current SC Clearance a must. London 3 days a week Immediately interviewing.
- Contract Night Shift Senior SOC Analyst | Microsoft Defender | Outside IR35
- United Kingdom
- Outside IR35
Contract Night Shift Senior SOC Analyst | Microsoft Defender / Sentinel | Outside IR35 Looking for an experienced SOC analyst to cover a night shift SOC operation. Level 2 technical Analyst. You must have current hands on technical experience with Microsoft defender / Sentinel within a customer facing SOC environment. This is a UK based position.
- DV Cleared CyberArk Consultant- Contract
- City of London
- Upto £700 per day
CyberArk Consultant is needed to be responsible for leading the deployment of CyberArk solutions for this Secure government site You will work with customer, helping to create CyberArk Strategic Roadmaps, on-boarding accounts, product and process integration into the CyberArk Solution and Proviso of Installation and technical Documentation. We are looking for this individual to have experience in: In CyberArk deployment, and ideally leady the deployment both strategically and also technically for this project we need the consultant to hold current DV cleared status For the right individual this could be a long term project.
- CyberSecurity Portfolio manager
- upto €60,000 plus benefits
A cybersecurity rockstar with a strategic mind and a passion for building winning solutions, is required to craft a cutting-edge security portfolio for an expanding IT Services business , with the aim to develop solution & services that will protect their customers business. this role will involve, develop & implement security strategies, manage the portfolio, drive sales, and collaborate with teams across the globe. we are looking for someone with experience in managing and building a cybersecurity portfolio of service a knack for building relationships & leading diverse teams Strategic vision & the ability to translate it into action strong communication & collaboration skills