Yes, that is a Moose taking control of your Instagram

Credit: Flickr (David Bailey)

Home routers, cable and DSL modems have been exploited by hackers using malware that can be implemented to botnets to take control of Twitter, Instagram and a range of other social media accounts.

A report penned by security researchers Olivier Bilodeau and Thomas Dupuy from security firm ESET found that the Linux/Moose malware has been targeting consumer routers and modems that have weak credentials, not exploiting any kind of vulnerability.

Once the Moose is loose about in your router, it can eavesdrop on communications to and from devices whether it be a laptop, smartphone, tablet or any other peripheral that uses a router to connect to the internet (regardless of whether it is MIPS or ARM-based).

From here it can do its worst, which in this case is hijacking social media accounts and turning them into spam bots.

"The operators use the infected devices to perform social network fraud on Twitter, Facebook, Instagram, Youtube and more," said the two researchers. "Moose can be configured to reroute router DNS traffic, which enables man-in-the-middle attacks from across the Internet."

Twitter worst affected

An analysis carried out by the pair found that Twitter/Vine accounted for 49% of the targets, Instagram 47% and Soundcloud 2%, with the remaining 3% made up of Yandex, YouTube, Yahoo and Amazon Cloud.

Thankfully when a router is switched off, the Linux/Moose malware disappears, however, if the credentials are left poorly configured then it can easily re-infected the device and users are encouraged to firm up their router to prevent their accounts falling victim to the exploit.

TOPICS
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening