In windows 10, my wifi router appears under 'network infrastructure' as 'R7000 (Gateway)' Open file explorer (the folder icon on the taskbar) Once again, make sure your router firmware is up-to-date, disable external WAN access, and change your default password.Īnd lo ~ I have a router update! thnx for the heads up! (even updated just a month ago). These include online banking sites but also Netflix and hosting companies. As soon as the users browse to specific websites they are redirected to phishing sites. In total, more than 100,000 routers are affected by the attack of which the majority is located in Brazil. The current attack, discovered by network security lab 360 Netlab, affects more than 70 different routers: Currently, the attacks are mainly active in Brazil. Once the criminals are able to login they change the DNS server address of the router.
While not a new methodology, from the 20th of September of this year a large attack was discovered by security researchers. So basically on a malicious website, a script would be executed that sniffs if your router port is open, try to log in (brute force) to your router, that changes credentials and DNS. A lot of users use the default username and password which makes them extra vulnerable. That way traffic can be re-routed ending up at phishing sites etc. Over a 100K routers from brands like D-Link, MikroTik, TP-Link, Huawei and SpeedTouch are currently hijacked and have a changed the DNS server.