Live data from Hacker News

Someone Has Infected at Least 500,000 Routers All Over the World

motherboard.vice.com

1–10 of 30 posts

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#2
According to DOJ [1], "Someone" is Fancy Bear [2] and the FBI has seized control [3] of the C&C domain (ToKnowAll.com)

[1] https://www.justice.gov/opa/pr/justice-department-announces-...

[2] https://en.wikipedia.org/wiki/Fancy_Bear

[3] https://www.engadget.com/2018/05/24/fbi-seizes-domain-russia...

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#3
The journalism on this is awful. The Ukrainian statements are ridiculous and should have been challenged by VICE rather than sensationalized.

A state actor isn't going to run the kill command on 500,000 routers to disrupt a soccer match.

The intention of the compromise is for surveillance.

Not nearly as sophisticated as the NSA capabilities - nearly every router in the world (besides the small percentage not produced in the United States) are compromised by the NSA. It's telling how weak the Russian cyber security program is that they need to compromise routers with an active exploit to get some small surveillance capability. It also sounds like the C&C network didn't get a lot of investment, as its design was easy to subvert.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#5
post #2

According to DOJ [1], "Someone" is Fancy Bear [2] and the FBI has seized control [3] of the C&C domain (ToKnowAll.com) [1] https://www.justice.gov/opa/pr/justice-department-announces-... [2] https://en.wikipedia.org/wiki/Fancy_Bear [3] https://www.engadget.com/2018/05/24/fbi-seizes-domain-russia...

Any evidence or press release is enough?

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#6

Of all the routers world wide, this has to be a pretty small percentage, right? How many does it take to create an effective DDoS?

Depends on the target site. With half a million routers you could cause problems to 99% of sites out there. The percentage of websites that could handle 500k concurrent connections is very small.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#7
post #2

According to DOJ [1], "Someone" is Fancy Bear [2] and the FBI has seized control [3] of the C&C domain (ToKnowAll.com) [1] https://www.justice.gov/opa/pr/justice-department-announces-... [2] https://en.wikipedia.org/wiki/Fancy_Bear [3] https://www.engadget.com/2018/05/24/fbi-seizes-domain-russia...

Any evidence or press release is enough?

https://blog.talosintelligence.com/2018/05/VPNFilter.html provides a detailed technical overview of how VPNFilter functions and their findings conclude it appears to be a derivative of similar efforts by the same group.

NCCIC released the following analysis last year with more on the topic: https://www.us-cert.gov/sites/default/files/publications/AR-...

Sophos published an article a month ago that warned about this exact scenario: https://nakedsecurity.sophos.com/2018/04/18/russias-grizzly-...

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#10
post #6

Of all the routers world wide, this has to be a pretty small percentage, right? How many does it take to create an effective DDoS?

Depends on the target site. With half a million routers you could cause problems to 99% of sites out there. The percentage of websites that could handle 500k concurrent connections is very small.

It's not so much as amount of connections but amount of small packets sent. I can handle 500k connections without problems with enough RAM. You don't need a lot of connections to DDOS someone, you only need a lot of small packets (~84 bytes) or in case of volume attack a lot of 1536 bytes packets.
Post reply on HN