Cisco routers are being targeted by custom Russian malware

security
(Image credit: Shutterstock)

Russian state-sponsored threat actors have built custom malware and are using it against old, unpatched Cisco IOS routers, a joint US-UK report has warned. 

The UK National Cyber Security Centre (NCSC), the US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) released a report in which they state that APT28, a group allegedly affiliated with the Russian General Staff Main Intelligence Directorate (GRU), developed a custom malware named “Jaguar Tooth”. 

This malware is capable of stealing sensitive data passing through the router, and allows threat actors unauthenticated backdoor access to the device.

Stealing data

The attackers would first scan for public Cisco routers using weak SNMP community strings, such as the commonly used “public” string, BleepingComputer reports. As per the publication, SNMP community strings are like “credentials that allow anyone who knows the configured string to query SNMP data on a device”. 

If they find a valid SNMP community string, the attackers will look to exploit CVE-2017-6742, a six-year-old vulnerability that allows for remote code execution. That allows them to install the Jaguar Tooth malware directly into the memory of Cisco routers. 

"Jaguar Tooth is non-persistent malware that targets Cisco IOS routers running firmware: C5350-ISM, Version 12.3(6)," the advisory reads. "It includes functionality to collect device information, which it exfiltrates over TFTP, and enables unauthenticated backdoor access. It has been observed being deployed and executed via exploitation of the patched SNMP vulnerability CVE-2017-6742."

The malware will then create a new process called “Service Policy Lock” that gathers all the output from these Command Line Interface commands and harvests them using TFTP: 

  • show running-config
  • show version
  • show ip interface brief
  • show arp
  • show cdp neighbors
  • show start
  • show ip route
  • show flash

To address the problem, admins should update their Cisco routers’ firmware immediately. Furthermore, they can switch from SNMP to NETCONF/RESTCONF on public routers. If they can’t switch from SNMP, they should configure allow and deny lists to limit who can access the SNMP interface on internet-connected routers. Also, the community string should be changed to something stronger.

The advisory also says admins should disable SNMP v2 or Telnet.

 Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
China
Chinese hackers targeting Juniper Networks routers, so patch now
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
China
Juniper patches security flaws which could have let hackers take over your router
China
Salt Typhoon hackers used this clever technique to attack US networks
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does