Home / Tech News / Malicious Cisco router backdoor found on 79 more devices, 25 in the US (Dan Goodin/Ars Technica)

Malicious Cisco router backdoor found on 79 more devices, 25 in the US (Dan Goodin/Ars Technica)

The highly clandestine attacks hitting Cisco Systems routers are much more active than previously reported. Infections have hit at least 79 devices in 19 countries, including an ISP in the US that’s hosting 25 boxes running the malicious backdoor. That discovery comes from a team of computer scientists who probed the entire IPv4 address space for infected devices. As Ars reported Tuesday, the so-called SYNful Knock router implant is activated after receiving an unusual series of non-compliant network packets followed by a hardcoded password. By sending only the out-of-sequence TCP packets but not the password to every Internet address and then monitoring the response, the researchers were able to detect which ones were infected by the backdoor. Further Reading Security firm FireEye surprised the security world on Tuesday when it first reported the active outbreak of SYNful Knock. The implant is precisely the same size as the legitimate Cisco router image, and it’s loaded each time the router is restarted. It supports up to 100 modules that attackers can tailor to the specific target. FireEye found it on 14 servers in India, Mexico, the Philippines, and Ukraine. The finding was significant, because it showed an attack that had long been theorized was in fact being actively used. The new research shows it’s being used much more widely, and it’s been found in countries including the US, Canada, the UK, Germany, and China

Visit site:
Malicious Cisco router backdoor found on 79 more devices, 25 in the US (Dan Goodin/Ars Technica)

About Tech News Reporter

Check Also

EBay paid $573M to buy Japanese e-commerce platform Qoo10, filing reveals

EBay is a very distant second behind Amazon when it comes to e-commerce sales in the U.S., but abroad — and in particular in Asia — it is willing to invest to grow its footprint in a targeted way. In February, eBay paid a total of $573 million to acquire Qoo10, a Japanese sales platform, according to the company’s quarterly earnings filing . In more detail, the deal consisted of $306 million in cash and the relinquishment of about $266 million in shares in Giosis, a pan-Asian e-commerce marketplace business originally founded as a joint venture with Korea’s Gmarket. Qoo10, which claims two million shoppers, was originally part of Giosis. The acquisition is similar to a deal eBay did in Korea in 2001 when it purchased Internet Auction Co and linked the Korean service up to its global network of buyers and sellers. That integration has been successful, and today South Korea is eBay’s fourth largest market based on revenue behind only the U.S., Germany and UK, respectively. Although the acquisition of Qoo10 was first announced in February , the actual price was not disclosed until the company’s earnings report dropped on Thursday. “We believe the acquisition will allow us to offer Japanese consumers more inventory and grow our international presence,” eBay explained in the filing. The deal underscores how eBay is at the same time pulling back from general plays while doubling down on more targeted opportunities. Earlier this year, the company gave up its stake in Flipkart as part of its acquisition by Walmart, but at the same time committed to investing in a new, standalone eBay operation in India , using some of the $1.1 billion in proceeds it made from selling its Flipkart stake to Walmart. EBay had an unsuccessful effort in China which  ended in 2006  and it hasn’t returned to the country. According to its latest financial results, the company’s U.S.-based business accounted for $1.1 billion out the company’s total quarterly sales of $2.6 billion. That North American revenue was up five percent year-on-year, but eBay’s revenue from other international locations grew by more over the same period to give the company’s total sales a nine percent annual increase. That didn’t impress investors, however, and the company’s share price dropped by 10 percent to close Thursday at $34.11. EBay doesn’t break out revenue for Japan — where Qoo10 operates — but revenue from Korean rose by 13 percent to $304 million in the most recent quarter. Sales for ‘rest of the world’ were up nine percent to $505 million

Leave a Reply

Your email address will not be published. Required fields are marked *