Hidden For 6 Years, 'Slingshot' Malware Hacks Your PC Through Your Router

14 March, 2018, 04:50 | Author: Sammy Rose
  • Sophisticated malware attacks through routersMore

Security researchers at Kaspersky Lab discovered the malware, nicknamed Slingshot, that targets MikroTik routers through a multi-layer attack utilised to spy on users' PCs. According to Kaspersky's researchers, it is so advanced that it was likely a state-sponsored development.

The main objective of this malware does seem to be counter-espionage, Kaspersky notes patterns consistent with other such examples, but because it operates in kernel there are no limitations to the information it can collect. Credit card numbers, password hashes and identification codes (such as social security numbers), are just a few examples, but it is essentially any dataset.

"The discovery of Slingshot reveals another complex ecosystem where multiple components work together in order to provide a very flexible and well-oiled cyber-espionage platform".

The malware has been christened as Slingshot, which smartly exchanges the legitimate scesrv.dll file of the users with another a malicious one in the Windows library system. During these attacks, the group behind Slingshot appears to compromise the routers and place a malicious dynamic link library inside it, that is a downloader for other malicious components.

It can bypass security measures, such as Driver Signature Enforcement, by loading signed vulnerable drivers and running its own code through those security holes.

That includes a kernel-mode module called Cahnadr, and a user-mode module called GollumApp.

Kaspersky researchers found it can capture screenshots, keyboard data, network data, passwords, USB connections, other desktop activity, and clipboard data.

Wayne Rooney pens tribute to Michael Carrick on Twitter
Carrick moved to the Old Trafford in 2006 from Tottenham Hotspur and won five Premier League titles and a Champions League with the Red Devils.

Buveur d'Air Claims The Champions Hurdle At Cheltenham
The concluding Close Brothers Novices' Handicap Chase went to Mick Channon's 13-2 shot Mister Whitaker, ridden by Brian Hughes. Last seen winning the Tolworth at Sandown, he quickened up well to deny Amy Murphy's Kalashnikov in the final few strides.

National Basketball Association roundup: Timberwolves go to Towns in 109-103 win vs. Warriors
This will be another hard week for the Warriors to grind through all these minor but not insignificant injuries. Still, Kerr was satisfied with his short-handed team. "More than anything, we just looked a little exhausted ".

Over half the compromised computers were in Kenya and Yemen, with the remainder in Libya, Afghanistan, Iraq, Tanzania, Greece, Jordan, Mauritius, Somalia, Tunisia, Turkey, and United Arab Emirates.

Kaspersky didn't speculate as to why machines in these nations were targeted.

That's likely why a nation-state is behind the attack. However, the researchers did discover debug messages within the code that were written in flawless English. Coincidence? We're not so sure. Text clues in the code suggest it is English-speaking; however, accurate attribution is always hard, if not impossible to determine, and increasingly prone to manipulation and error. It's called Slingshot and it was recently discovered by Kaspersky Labs.

After a router is infected, the malware would load a couple of "huge and powerful" modules on the target's computer. Despite being in the wild since 2012 - and still being in operation during the last month - Slingshot has, until now, avoided detection. For example, it was able to hide from detection by using an encrypted virtual file system that as cloaked in an unused part of a hard drive. Slingshot is also capable of accessing the data on an infected machine's hard drive or internal memory due to the ability to access an operating system's kernel level.

"Slingshot is very complex, and the developers behind it have clearly spent a great deal of time and money on its creation", company researchers wrote. "Its infection vector is remarkable - and, to the best of our knowledge, unique", the researchers noted and explained that as of February 2018 Slingshot still appears to be active. And while the infected routers that have been identified will be fixed via software updates, there's no telling how many machines may have been affected.

"The malicious samples investigated by the researchers were marked as "version 6.x", which suggests the threat has existed for a considerable length of time", the team said in a blog post.


  • Mo Wilkerson agrees to terms with Packers on free-agent deal

    Mo Wilkerson agrees to terms with Packers on free-agent deal

    A Pro Bowler in 2015 and twice a second-team All-Pro, Wilkerson will help strengthen the Packers' front-seven. The Packers won the race for Wilkerson's service. "#Packers should be getting a motivated player".

    Ross Stores (ROST) Stock Rating Lowered by Zacks Investment Research

    Hilltop Holdings Inc increased Ishares Tr (EFA) stake by 27,118 shares to 96,423 valued at $6.60 million in 2017Q3. Fossil Group, Inc ., ( NASDAQ: FOSL ), showed a change of -7.64% and closed at $12.57 in the last trading session.
    Eagles release TE Brent Celek, their longest-tenured player

    Eagles release TE Brent Celek, their longest-tenured player

    Prior to the 2016-17 season, the Eagles and Johnson agreed to a six-year, $63 million contract with over $35 million guaranteed. Ngata had just two sacks in five games a year ago , but when healthy, he is a healthy run-stuffer.
  • Don't believe the hype about the coming solar storm

    Don't believe the hype about the coming solar storm

    The initial news on the massive geomagnetic storm appeared on Monday, and soon after fired up Google News. The category rises from G1 to G5 with the increase in the intensity of the geomagnetic storms.

    NXP Semiconductors (NASDAQ:NXPI) Upgraded by BidaskClub to "Hold"

    Elizabeth Park Capital Advisors Ltd. holds 3.73% of its portfolio in Regions Financial Corporation for 631,470 shares. RBC Capital Markets maintained Endo International plc (NASDAQ:ENDP) on Tuesday, October 17 with "Hold" rating.
    Google Assistant Lands on the iPad

    Google Assistant Lands on the iPad

    So, if you're an Apple user who happens to enjoy Google's services, you now have more options when it comes to using Google Assistant on iOS .
  • Bamco Inc. NY Lowers Holdings in Halliburton

    On Tuesday, January 9 the insider Beaty Anne L . sold $83,844. $409,607 worth of Synopsys, Inc. (NASDAQ:AKAM) for 11,700 shares. Also, insider Timothy Mckeon sold 1,609 shares of the firm's stock in a transaction that occurred on Wednesday, December 27th.
    'Buffy' revival a possibility, but only with creator Joss Whedon

    'Buffy' revival a possibility, but only with creator Joss Whedon

    However, the network has built up a reputation for bringing back their successful series. There are several Buffy the Vampire Slayer podcasts like "Buffering" or " Buffy Talk".
    Tottenham's Kane out until end of April

    Tottenham's Kane out until end of April

    Kane left the field against Bournemouth with an ankle problem and the damage remains unknown. Kane's history of injuries to his right ankle is a concern.
  • Twitch Offering More Free Games to Prime Subscribers Each Month

    Twitch Offering More Free Games to Prime Subscribers Each Month

    Twitch announces Free Games with Prime , which gives Amazon (NASDAQ: AMZN ) customers access to free games to download each month. There will be five games given away this month which includes Superhot, Shadow Tactics, Tales from Candlekeep, Oxenfree , and Mr.
    National Geographic magazine acknowledges its racist past

    National Geographic magazine acknowledges its racist past

    Let's not exactly say, "At least they're doing this now", but simply, as a matter of fact, "They're doing this now". Mason also uncovered a string of oddities-photos of "the native person fascinated by Western technology.
    Arrieta ready to help Phillies win

    Arrieta ready to help Phillies win

    The process of finding a new home may have taken longer than he expected, and he may not have gotten everything he wanted. "Maybe. The Phillies only have three players - Arrieta, Carlos Santana , and Odubel Herrera - under contract after next season.


Seattle Seahawks Players Get Harassed Over Anthem Protests
The players asked the woman for her name - she refused to identify herself - instead, babbling and cussing away. There's a lot of cross-talk, but it's clear the players are more bemused by the ranting woman than bothered.

Houston Texans making 'strong run' at New England Patriots tackle, per report
Pittsburgh Steelers' right tackle Chris Hubbard is another nice option for the Giants as well reports ESPN's Jordan Raanan . He noted the Patriots will have stiff competition in signing Solder because Cleveland has "a ton of money to play with".

This Is Us: our expectations for the Season 2 finale
While that was the signature event in these characters' lives, Tuesday's episode served notice that life goes on. We decided we wanted something that was sort of vintage in its own way, but very classic, but still contemporary.

Klopp confirms Liverpool boost for Old Trafford trip
Klopp picked out counter-pressing, good decision making and fantastic attitude as being vital for Liverpool at Old Trafford. Big rivalry for ages but in the last few years Man United were more successful than us, we respect that.

Trump considering Rick Perry to take over VA
If Shulkin is fired it would be the latest major shakeup in the Trump administration. Perry had lunch with Trump at the White House on Monday.

The Flash: Fans Haven't Figured Out Mystery Girl's Identity
As revealed before , Kennedy confirmed that there is more to her character and she will come back at least "one more time ". For her part, Patton is fine with getting to be a speedster for only a short amount of time .

Family Of Woman Killed In Yountville Tragedy Mourns Loss
He served in active duty from May 2010 to August 2013 and was deployed to Afghanistan from April 2011 to March 2012. Jerry Brown had offered the state's employee assistance program, which had already sent counsellors to the campus.

Trump wants the USA military to have a 'space force'
The President said the idea of an out-of-this-world battle squad started as a joke, before he warmed to the idea. After extensive politicking the US Congress passed the 2018 National Defense Authorization Act in November.

New York Jets, Teddy Bridgewater Working On Deal
Bridgewater, meanwhile, is gradually working his way back from a serious knee injury that cost him most of the past two seasons. That changed in August 2016, however, after a devastating knee injury put his National Football League future in jeopardy.

Toys 'R' Us said to miss vendor payments
The bleak situation lends evidence to the notion that Toys "R" Us is moving toward winding down its USA operations for good. Toys R Us in January had announced it was going to shut down 182 locations, including five in upstate NY .