All the latest UK technology news, reviews and analysis

Trend Micro warns of Linux malware spreading on routers

by Iain Thomson

11 Mar 2011

Be the first to comment

  • Tweet this
Concept image representing virus malware

Trend Micro has issued a warning to administrators after picking up the first copies of a Linux malware variant infecting routers.

The ELF_TSUNAMI.R malware uses a combination attack to spread. It is capable of running its own brute force attacks against routers, but also exploits a flaw in the D-Link DWL-900AP+ internet router. The code also links infected machines to botnet servers via IRC channels.

"This malware is predominantly found in Latin America but we are also checking the extent of infection in other regions," Trend Micro warned in a blog post.

"The attacks also work against D-Link routers, and we are also verifying if it works on others."

The malware is thought to be a variant of a strain first discovered in 2008, but which has since been adapted and made more efficient.

Malware writers generally stick to trying to infect end-user systems, but attacks on network hardware are not unknown.

"There is a long history of router-centric attacks going back at least three years and coincides especially with the growth of Wi-Fi," Rob Rachwald, Imperva's director of security strategy, told V3.co.uk.

"Why? Hackers would love to have the ability to route all the victim's traffic to perform, for example, DDoS or mass SQL injection attacks."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Support Analyst

IT Support Analyst (initial 6 month fixed term) Cirencester...

Java Developer - Grad / Web / Mobile - Manchester

Java Developer - Graduate / Budding Superstar opportunity...

Solutions Consultant - JEE, PHP, Project Lead - Midlands

Solution Consultant - JEE, Support, Project Lead, SQL...

C++ Developer - Financial Vendor

C++ Developer - C++, STL, Boost, Delphi, Concurrency...

To send to more than one email address, simply separate each address with a comma.