Live data from Hacker News

Someone Has Infected at Least 500,000 Routers All Over the World

motherboard.vice.com

11–20 of 30 posts

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#11

I'd love to know how I could detect if anything on my network is infected -- are there any IPs/DNS that I could look out for in my logs?

The Talos blog below goes much further in depth on whats actually happening (ip is extracted from photo location data)

Link to blog: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#13
post #6

Of all the routers world wide, this has to be a pretty small percentage, right? How many does it take to create an effective DDoS?

Depends on the target site. With half a million routers you could cause problems to 99% of sites out there. The percentage of websites that could handle 500k concurrent connections is very small.

If we assume each router has, on average, 0.5Mbps upstream (hopefully it's higher!) then that's a combined capacity of ~250Gbps.

Some quick searching says the average DDOS size at one point in 2017 was measured at ~14Gbps and some larger attacks were peaking at ~120Gbps. Cloudflare's "biggest DDOS ever" was 800Gbps.

Even if we assume a lot of these routers are clustered on specific ISPs or networks and the effective capacity will be less, just on sheer bandwidth we're still well into or above the range of some of the larger DDOS attacks.

Whatever way you look at it, I'm sure 500,000 routers is enough to cause some trouble for most people.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#14
post #8

Seems like a lot of trouble to go through in order to disrupt a soccer game.

That's because there's no way its intention is to disrupt a soccer game.

That's Ukraine's intelligence sector's way of driving popular "regular Joe" attention to a security interest that they have (by misleading them about the purpose).

What's disappointing is that the VICE article bothers to repeat it.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#16
The state of SOHO router security is pretty sad. Sure, most of those infected were probably unpatched, possibly had remote-admin pages enabled, or were using default credentials but... why is it even possible to open the remote admin interface with default passwords?

Why don't they all auto-update by default for critical vulnerabilities?

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#17
post #15

Why not post the original Cisco report. This article barely grazes over the topic

I choose this because it links to most of the relevant articles (including the Talos blog & US National Cybersecurity advisory) in the body of the Motherboard article.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#18
post #6

Earlier quoted context omitted.

Depends on the target site. With half a million routers you could cause problems to 99% of sites out there. The percentage of websites that could handle 500k concurrent connections is very small.

If we assume each router has, on average, 0.5Mbps upstream (hopefully it's higher!) then that's a combined capacity of ~250Gbps. Some quick searching says the average DDOS size at one point in 2017 was measured at ~14Gbps and some larger attacks were peaking at ~120Gbps. Cloudflare's "biggest DDOS ever" was 800Gbps. Even if we assume a lot of these routers are clustered on specific ISPs or networks and the effective…

[deleted]

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#19
post #2

According to DOJ [1], "Someone" is Fancy Bear [2] and the FBI has seized control [3] of the C&C domain (ToKnowAll.com) [1] https://www.justice.gov/opa/pr/justice-department-announces-... [2] https://en.wikipedia.org/wiki/Fancy_Bear [3] https://www.engadget.com/2018/05/24/fbi-seizes-domain-russia...

I believe this is what Antonov meant when he said: "A pre-designed scenario is being implemented, Again, we are being threatened. We warned that such actions will not be left without consequences." in response to the latest Syria strike.

WWIII may not be nukes, but complete economic chaos after banks, hospitals, militaries, and electricity networks are taken down.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#20
post #2

According to DOJ [1], "Someone" is Fancy Bear [2] and the FBI has seized control [3] of the C&C domain (ToKnowAll.com) [1] https://www.justice.gov/opa/pr/justice-department-announces-... [2] https://en.wikipedia.org/wiki/Fancy_Bear [3] https://www.engadget.com/2018/05/24/fbi-seizes-domain-russia...

I believe this is what Antonov meant when he said: "A pre-designed scenario is being implemented, Again, we are being threatened. We warned that such actions will not be left without consequences." in response to the latest Syria strike. WWIII may not be nukes, but complete economic chaos after banks, hospitals, militaries, and electricity networks are taken down.

Good reasons to start being a prepper if you aren't already
Post reply on HN