Sunday, May 25, 2025
HomeDNSHackers Hijack Home Routers & Change The DNS Settings to Implant Infostealer...

Hackers Hijack Home Routers & Change The DNS Settings to Implant Infostealer Malware

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new form of attack that targeted home routers and altered the DNS settings to redirect the victims to a malicious website that delivers the infostealer malware called “Osk” which seems to have emerged in late 2019.

Landing websites are posing with information about the Coronavirus pandemic and force victims to download the app that promises victims to provide “the latest information and instructions about coronavirus (COVID-19)” through the app.

COVID-19 Theme is nowadays badly abused to trap victims using phishing attacks and exploit the victims to steal sensitive data.

- Advertisement - Google News

Attackers also use Bitbucket, the popular web-based version control repository hosting service to store the malicious payload, and the Popular URL shorten service TinyURL to hide the link that redirects users to reach the Bitbucket.

Researchers from Bitdefender reported the following key finding of this attack

1.Mostly targets Linksys routers, bruteforcing remote 
management credentials
2. Hijacks routers and alters their DNS IP addresses
3. Redirects a specific list of webpages/domains to a
malicious Coronavirus-themed webpage
4. Uses Bitbucket to store malware samples
5. Uses TinyURL to hide Bitbucket link
6 . Drops Oski inforstealer malware

Compromising The Routers

The attacker probes the internet to find the vulnerable home router to perform the password brute-forcing attack and change the DNS IP settings.

DNS setting is playing an important role in resolving the right IP address to the corresponding domain names.

If the attackers change the DNS IP addresses from the targeted routers, it resolves the user request to any web page that is controlled by the attacker.

The following list of the domain is targetted in this campaign:

  • aws.amazon.com”
  • “goo.gl”
  • “bit.ly”
  • “washington.edu”
  • “imageshack.us”
  • “ufl.edu”
  • “disney.com”
  • “cox.net”
  • “xhamster.com”
  • “pubads.g.doubleclick.net”
  • “tidd.ly”
  • “redditblog.com”
  • “fiddler2.com”
  • “winimage.com”

Users will be redirected to the IP addresses ( 176.113.81.159, 193.178.169.148, 95.216.164.181 ) If the traffic passes through the compromised router and the user will try to reach the above domains.

Changing the DNS settings never raises any red flag and users would believe they’ve landed on a legitimate webpage other than a different IP address.

“The webpages display a message purportedly from the World Health Organization, telling users to download and install an application that offers instructions and information about COVID-19,” Bitdefender said.

The attacker set the initial hyperlink to https://google.com/chrome which is a clean and well-known domain, but actually, an “on-click” event is set that changes the URL to the malicious one which is hidden with TinyURL.

Once victims click the download button, a malicious file drops from the Bitbucket repository but the victims are completely unaware of it.

“In the final stage of the attack, a malicious file packed with MPRESS is downloaded. This payload is the Oski stealer that communicates with a C&C server for uploading the stolen information.”

Bitdefender telemetry observed that most of the targeted vulnerable routers attempted to exploit were located in Germany, France, and the United States.

Also Read: What is DNS Attack and How Does it Work?

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets

A new project has exposed a critical attack vector that exploits protocol vulnerabilities to...

Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000

A threat actor known as #LongNight has reportedly put up for sale remote code...

Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability

Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager...

Hackers Target macOS Users with Fake Ledger Apps to Deploy Malware

Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Target macOS Users with Fake Ledger Apps to Deploy Malware

Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular...

GenAI Assistant DIANNA Uncovers New Obfuscated Malware

Deep Instinct’s GenAI-powered assistant, DIANNA, has identified a sophisticated new malware strain dubbed BypassERWDirectSyscallShellcodeLoader. This...

New Formjacking Malware Targets E-Commerce Sites to Steal Credit Card Data

A disturbing new formjacking malware has emerged, specifically targeting WooCommerce-based e-commerce sites to steal...