Cisco router attacks hit 4 countries including India: FireEye

Cisco routers in India, Ukraine, Philippines and Mexico have been attacked by a sophisticated malicious software that possibly allows cybercriminals to harvest huge amounts of data without being detected, security solutions firm FireEye said today.

cisco
Betting big on India as an investment spot, Cisco executive chairman John Chambers today suggested businesses not to 'miss the bus' as the country is in sync with the speed of innovation in the current digital age.

Cisco routers in India, Ukraine, Philippines and Mexico have been attacked by a sophisticated malicious software that possibly allows cybercriminals to harvest huge amounts of data without being detected, security solutions firm FireEye said today.

These routers are installed at strategic locations in India, including at AFNET — which is considered as a secure communication network for Indian Air Force.

The US-based firm is a major supplier to many Indian telecom companies as well.

The attack, which uses a highly sophisticated malicious software called SYNful Knock, has been implanted in routers made by Cisco, FireEye said in its report.

“Mandiant (a FireEye company) can confirm the existence of at least 14 such router implants spread across four different countries: Ukraine, Philippines, Mexico and India,” it added.

Cisco confirmed the attacks saying it has recently alerted its customers to a new sort of attack against networking devices.

“These attacks do not exploit vulnerabilities, but instead use compromised credentials or physical access to install malware on network devices. We’ve shared guidance on how customers can harden their network and prevent, detect and remediate this type of attack,” a Cisco spokesperson said.

FireEye said the router’s position in the network makes it an ideal target for re-entry or further infection.

“The impact of finding this implant on your network is severe and most likely indicates the presence of other footholds or compromised systems. This backdoor provides ample capability for the attacker to propagate and compromise other hosts and critical data using this as a very stealthy beachhead,” it said.

Hackers attack routers as they operate outside the boundaries of firewalls, anti-virus and other security tools that organisations use to safeguard their data traffic.

FireEye said its findings represent the tip of the iceberg on the issue and that further research will be needed to assess the extent of the issue.

Get live Share Market updates, Stock Market Quotes, and the latest India News and business news on Financial Express. Download the Financial Express App for the latest finance news.

This article was first uploaded on September fifteen, twenty fifteen, at ten minutes past eleven in the night.

Photo Gallery

View All
Market Data
Market Data