European national computer emergency response teams and international cyber authorities have issued high-priority advisories following telemetry confirming that over 100,000 MikroTik routers running RouterOS have been enslaved in a pervasive, globally distributed compromise campaign. Widely deployed across internet service providers, municipal utilities, and small-to-medium enterprises, MikroTik routing hardware represents a strategic target for cyber adversaries seeking resilient command-and-control relay infrastructure.
Forensic telemetry reveals that threat actors leverage a blend of legacy remote execution vulnerabilities (including CVE-2018-14847 and CVE-2023-30799) combined with automated credential stuffing attacks (credential stuffing) directed against internet-exposed Winbox (TCP port 8291) and WebFig (TCP ports 80/443) management interfaces.
Upon seizing administrative control of a target router, adversaries alter local DNS resolution entries, enable covert SOCKS5 proxy listeners, and install persistent maintenance scripts scheduled via RouterOS cron utilities to survive appliance reboots. The compromised router fleet is actively monetized across illicit dark web clearinghouses (cybercrime), leased out as anonymous residential proxies to conceal ransomware operations, banking trojan telemetry, and distributed denial-of-service (DDoS) barrages against critical infrastructure (infra-terror).
MikroTik has urged all network operators to immediately deploy the latest stable RouterOS v7 firmware branch and terminate external internet exposure of all local administration daemons.
Telemetry gathered across major international Internet Exchange Points (IXPs) indicates that the enslaved MikroTik hardware is structured into a multi-tiered, resilient mesh proxy topology. Adversaries establish encrypted overlay tunnels to route operational traffic from international ransomware syndicates through benign small-business routers. Consequently, when forensic investigators and incident response teams attempt to trace adversarial command infrastructure, forensic attribution terminates at an unwitting local business, medical clinic, or educational facility hosting an unhardened edge router.
Instructions de sécurisation pour administrateurs réseau
- Upgrade to RouterOS v7 Long-Term Immediately: Execute firm software upgrades across all routing hardware to patch known privilege escalation and memory corruption flaws.
- Block Public WAN Access to Winbox and WebFig: Restrict management interfaces (ports 8291, 80, 443) strictly to authenticated local management subnets or encrypted VPN tunnels (WireGuard / IPsec).
- Deprecate Default Administrative Accounts: Disable the built-in 'admin' account and provision randomized credentials reinforced by cryptographically secure key authentication.
- Audit System Scripts and SOCKS Proxies: Inspect appliance configurations under `/system script`, `/system scheduler`, and `/ip socks` to eradicate rogue persistence daemons.
- Verify DNS Server Integrity: Validate that nameservers configured under `/ip dns` align precisely with trusted enterprise upstream providers.
État des preuves
- Confirmed: CERT advisories confirm more than 100,000 active MikroTik appliances infected with unauthorized proxy daemons.
- Reported: Internet service providers observe high-volume malicious traffic relays originating from compromised router nodes.
- Unconfirmed: Zero evidence exists of novel unpatched zero-days; all compromises trace back to known CVEs and exposed default ports.
En résumé
- Over 100,000 MikroTik routers worldwide compromised into cybercrime proxy networks via known vulnerabilities.
- Adversaries alter DNS tables, install rogue SOCKS proxies, and use enslaved hardware to obscure ransomware attacks.
- Operators must immediately apply RouterOS v7 updates and block public WAN exposure to administrative interfaces.