• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Victims Infected Through MicroTik Routers in Latest Cyber-Espionage Group Attack

March 12, 2018Simeon Georgiev

Kaspersky Lab has uncovered the existence of a new cyber-espionage group that uses MikroTik routers to infect users with an attack that many researchers and analysts in this field have called very unique. Experts studying this case have codenamed the group behind the attack as Slingshot and according to latest evidence it is believed that the group started operations back in 2012. The group was still found to be active in Feb of 2018, so reports of the attacks can be trusted.

Experts from Kaspersky believe that because this group has been active for more than half a decade, they used extremely complex malware. The operations were very specifically targeted and Slingshot appeared to be different from the run of the mill cyber-criminal operation focused on profits. It is currently expected that Slingshot is a state-sponsored group different from other cyber-criminals.

Relied on Windows Exploits

One thing that impressed Kaspersky from the whole operation was level of complexity that Slingshot showed in their entire hacking process. The malware that they possessed was expensive to develop, may have required a lot of time to create, was sophisticated, had an innovative method of delivery and did not trigger any errors whatsoever. Although Slingshot did rely on classic Windows exploits for most of their cases, a few attacks that were different from the others were carried out through MikroTik routers.

The group made use of these routers as points for delivering the payloads to their desired targets. This was done through the use of Winbox Loader, which is an application by MikroTik, in helping users configure the routers. The app basically works by downloading DLLs from within the router itself. However, what Slingshot did was to replace these files with other malicious ones that infected the users when they reconfigured or configured their router through the app for Winbox Loader. 

Researchers working on the events have found out that Slingshot usually infects users with two distinct families of malware, which include Cahnadr and GollumApp. Cahnadr is usually detected by researchers as NDriver.

For assistance with file recovery and ransomware removal, please contact MonsterCloud – cyber security experts for a professional ransomware removal.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Hackers Slam Tor Proxy Service Blaming Onion.top for Diverting Ransom Money Next post “Police themed” – How to remove ransomware

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

BitPaymer Ransomware Traced Back to Dridex Developers

February 1, 2018Simeon Georgiev
BitPaymer Ransomware Traced Back to Dridex Developers

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.