Newly discovered malware targets routers

Kaspersky uncovers malware attacking through routers

Instead, it resides on a router. The team at Kaspersky believes activity started in at least 2012, and was active at the time of analysis in February six years later.

The researchers haven't named Slingshot's country of origin but note the presence of debug messages written in ideal English, while various component names such as Gollum and Smeagol suggest the authors are fans of The Hobbit. And while the infected routers that have been identified will be fixed via software updates, there's no telling how many machines may have been affected. "Taken together, these clues suggest that the group behind Slingshot is likely to be highly organized and professional and probably state-sponsored".

Unlike other less sophisticated pieces of malware, Slingshot is able to steal keystrokes, passwords, screenshots and nearly any information it wants from a users' system because of how well it was created to avoid detection which is why it has existed on the web since 2012.

The researchers haven't discovered how Slingshot infects MikroTik routers to use the WinBox bridge to the PC, however they note in a technical paper that WikiLeaks' Vault 7 leak of Central Intelligence Agency hacking tools did reference an exploit for MikroTik's router OS called ChimayRed.

According to Ars Technica, the sophistication of Slingshot rivals similarly advanced malware apps, including Regin, a backdoor that infected Belgian telco Belgacom and other targets for years, and Project Sauron, a separate malware that also remained hidden for years.

Over half the compromised computers were in Kenya and Yemen, with the remainder in Libya, Afghanistan, Iraq, Tanzania, Greece, Jordan, Mauritius, Somalia, Tunisia, Turkey, and United Arab Emirates. The two modules are connected and able to support each other in information gathering, persistence and data exfiltration. Interestingly enough, the vast majority of these instances are individuals not organizations or governments (though there are a few examples of the latter two). Kaspersky did not identify the malware's creators but said that debug messages were written in ideal English, suggesting developers spoke that language.

Slingshot protects itself by storing all of its malware files within an encrypted virtual file system and by encrypting every text string used in its modules.

According to Kaspersky's FAQ on Slingshot, the GollumApp module features almost 1,500 functions. It even shut down certain components when forensic tools were in use on the device. "Its infection vector is remarkable - and, to the best of our knowledge, unique".

Related News:

Most liked

Drug overdoses prompt warning from Saskatoon police about alleged drug dealer
During their investigation police said officers arrested three men and seized drugs that included the powerful opioid fentanyl. The 48-year-old woman has died and the 25-year-old woman, found unresponsive, is being treated in a hospital.

Caxton Associates LP Boosts Position in Check Point Software Technologies Ltd. (CHKP)
After $0.39 actual EPS reported by The Coca-Cola Company for the previous quarter, Wall Street now forecasts 20.51% EPS growth. The stock of Check Point Software Technologies Ltd. (NASDAQ:CHKP) earned "Hold" rating by Evercore on Tuesday, December 15.

Apple acquires digital magazine subscription service Texture
The service costs $9.99 per month after a free trial. "We could not imagine a better home or future for the service". The company, which has raised hundreds of millions of dollars, spent nearly $50 million on advertising in 2015.

Partly sunny, high near 34 — TODAY'S FORECAST
On Sunday , temperatures are forecast to hit 66 degrees with morning fog giving way to sunny skies in the Eugene area. Monday will see a 40 percent chance of snow after 2 p.m., decreasing to a 30 percent chance at night.

Jesse Eisenberg speaks on whether he's returning to play Lex Luthor
It's likely that he'll reprise the role in that movie's sequel, as well as the Joker/Harley Quinn film that is now in development. But fans still love watching the Superman movie and can not wait for Man of Steel 2 to begin production .

Ekweremadu denies report completely — Military coup
We also are talking about Kwankwaso, who was stopped from going to his state where he ruled for eight years. The party is planning to hold its non-elective national convention in April.

Farfetch poised to make £4bn IPO after hiring United States banks
Much of the online marketplace's capabilities were showcased at its inaugural conference in London one year ago. It aims to reach more customers online with the Farfetch deal, through which it will offer a selection of items.

Congress announces two more candidates for RS polls
Union minister Ravi Shankar Prasad and five others today filed their nominations for Rajya Sabha elections in Bihar. Congress President Rahul Gandhi approved the list for the the March 23 Rajya Sabha polls, the party said.

Collingwood could lose Tyson Goldsack for entire season
Goldsack, 30, has played 161 games since his 2007 debut and was a member of Collingwood's 2010 premiership team. There was no indication during or after the game that Goldsack had suffered the injury.

Endocrine System Drugs Market Specifications Analysis 2018
The growth of each of the market segments during the forecast horizon has been analyzed in the report. On the basis of regions, North America holds the major share in the global market, trailed by Europe.

Who will Charlotte Flair be facing at WrestleMania?
These are two of the top superstars in the entire company, and are personally my two favorite female competitors on the main roster.

Imam-e-Kaaba, PM Abbasi exchange views on issues concerning Muslim Ummah
He added that the strength of Pakistan is the strength of Saudi Arab and the power of Saudi Arab is the power of Pakistan. The CM said he is a great admirer of people friendly policies of Crown Prince Mohammad Bin Salman.

Government Confirms Online Porn Age Checks Delay
The system was developed by Pornhub's parent company Mindgeek and will work across multiple sites after initial registration. The Department of Culture, Media and Sport announced the delays to the introduction of the system over the weekend.

Manchester United's Michael Carrick confirms he will retire at end of season
As such, he's likely to take on a coaching role from next season - discussions are ongoing but "it's been kind of sorted out". Hopefully I can get some game time and I am still enjoying training. "I need to keep myself fit and ready.

Naidu laments disruptions in Parliament
He also expressed concern over lack of quorum in the House and said that he had to press the quorum bell on several occasions. He said, the elected representatives should not exaggerate things as it brings down the credibility.