Skip to content
DnsLister Forum

Where domain hunters compare notes

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Active exploitation of MikroTik RouterOS devices is underway, with attackers gaining full admin access via internet-exposed SSH—no authentication required. CERT Polska issued a warning on September 5, with confirmed attacks dating back to at least September 2. No victim count or attribution has been released yet.

Technical Breakdown – Attack Vector: Internet-facing SSH service on MikroTik routers (likely older or unpatched RouterOS versions). – Impact: Full administrative control over the device, enabling traffic interception, DNS hijacking, botnet recruitment, or pivot into internal networks. – No Authentication Required: Implies a critical authentication bypass or default credential abuse—CVE details pending or unconfirmed. – IOCs: None publicly available at this time. Monitor for unauthorized SSH sessions, unexpected config changes, or outbound connections from RouterOS devices.

Defense Immediately disable SSH access from the WAN interface. If remote management is required, restrict by source IP and use VPN or SSH key-only authentication. Update RouterOS to the latest stable version and audit for any unauthorized admin accounts or firewall rule changes.

Source: https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *