Banking hack attacks routers, warns Symantec

…SMEs be suspicious

NEWS

Security company Symantec has warned of an attack involving the subversion of routers.

Security A to Z

From antivirus to zero-day, click here for silicon.com's alphabetical guide to security.

The company said this was the first time it had seen such an attack "in the wild", although the concept had been discussed a year ago by Symantec researchers, according to a Symantec blog post.

In the attack, which targeted users of an undisclosed Mexican bank, the intended victims received a spam email claiming they had received an e-card, directing them to gusanto.com, a Spanish language e-card site. However, the email also had embedded HTML image tags, which contained a get-request to the router to change its DNS settings, according to Symantec's UK manager of quality assurance, Thomas Parsons.

The HTTP get-request redirects traffic flowing over the router to a specific IP address when the user attempts to access six domain names that are banking-related.

The attack is made possible by a cross-site scripting vulnerability in 2Wire routers that was reported in August last year, according to Symantec. Parsons said this was "a simple hack", and advised SMEs to change default security settings on routers, and educate users about clicking on suspicious links.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters