botnet-kill-switch

MikroTik botnet uses misconfigured SPF DNS records to spread malware

Teilen:

A newly discovered botnet of 13,000 MikroTik devices uses a misconfiguration in domain name server records to bypass email protections and deliver malware by spoofing roughly 20,000 web domains.

The threat actor takes advantage of an improperly configured DNS record for the sender policy framework (SPF) used for listing all the servers authorized to send emails on behalf of a domain.

Misconfigured SPF record

According to DNS security company Infoblox, the malspam campaign was active in late November 2024. Some of the emails impersonated DHL Express shipping company and delivered fake freight invoices with a ZIP archive containing a malicious payload.

Inside the ZIP attachment there was a JavaScript file that assembles and runs a PowerShell script. The script establishes a connection to the threat actor’s command and control (C2) server at a domain previously tied to Russian hackers.

“The headers of the many spam emails revealed a vast array of domains and SMTP server IP addresses, and we realized we had uncovered a sprawling network of approximately 13,000 hijacked MikroTik devices, all part of a sizeable botnet,” explains Infoblox.

Infoblox explains that SPF DNS records for about 20,000 domains were configured with the overly permissive “+all” option, which allows any server to send emails on behalf of those domains.

“This essentially defeats the purpose of having an SPF record, because it opens the door for spoofing and unauthorized email sending” – Infoblox

A safer choice is using the “-all” option, which limits email sending to the servers specified by the domain.

Overview of the botnet operation
Overview of the botnet operation
Source: Infoblox

MikroTik powering yet another botnet

The compromise method remains unclear but Infoblox says they “saw a variety of versions impacted, including recent [MikroTik] firmware releases.”

MikroTik routers are known for being powerful and threat actors targeted them to create botnets capable of very powerful attacks.

Just last summer, cloud services provider OVHcloud blamed a botnet of compromised MikroTik devices for a massive denial-of-service attack that peaked at a record 840 million packets per second.

Despite urging MikroTik device owners to update the systems, many of the routers remain vulnerable for extended periods of time because of a very slow patch rate.

The botnet in this case configured the devices as SOCKS4 proxies to launch DDoS attacks, send phishing emails, exfiltrate data, and generally help mask the origin of malicious traffic.

“Even though the botnet consists of 13,000 devices, their configuration as SOCKS proxies allows tens or even hundreds of thousands of compromised machines to use them for network access, significantly amplifying the potential scale and impact of the botnet’s operations,” comments Infoblox.

MikroTik device owners are advised to apply the latest firmware update for their model, change the default admin account credentials, and close remote access to control panels if not needed.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:39 pm, März 26, 2025
Wetter-Symbol 9°C
L: 7° | H: 10°
klarer Himmel
Luftfeuchtigkeit: 81 %
Druck: 1024 mb
Wind: 5 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 9%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:49 am
Sonnenuntergang: 6:22 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
7° | 10°°C 0 mm 0% 9 mph 88 % 1024 mb 0 mm/h
Fr. März 28 9:00 pm
Wetter-Symbol
7° | 11°°C 1 mm 100% 12 mph 91 % 1015 mb 0 mm/h
Sa. März 29 9:00 pm
Wetter-Symbol
4° | 12°°C 0 mm 0% 10 mph 81 % 1025 mb 0 mm/h
So. März 30 9:00 pm
Wetter-Symbol
5° | 14°°C 0 mm 0% 8 mph 76 % 1029 mb 0 mm/h
Mo. März 31 9:00 pm
Wetter-Symbol
9° | 17°°C 0 mm 0% 4 mph 84 % 1030 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
9° | 10°°C 0 mm 0% 4 mph 80 % 1024 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 4 mph 84 % 1024 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
8° | 8°°C 0 mm 0% 4 mph 88 % 1023 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 68 % 1023 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 50 % 1020 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 45 % 1018 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 8 mph 61 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
11° | 11°°C 0 mm 0% 8 mph 76 % 1017 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€80,853.27
-0.70%
Ethereum(ETH)
€1,865.66
-2.88%
Fesseln(USDT)
€0.93
-0.01%
XRP(XRP)
€2.18
-4.28%
Solana(SOL)
€127.28
-4.92%
USDC(USDC)
€0.93
0.00%
Dogecoin(DOGE)
€0.181418
2.53%
Shiba Inu(SHIB)
€0.000013
2.86%
Pepe(PEPE)
€0.000008
6.62%
Peanut das Eichhörnchen(PNUT)
€0.214428
7.85%
Nach oben scrollen