March 3, 2020 By Shane Schick 2 min read

Researchers estimate more than a billion devices may be vulnerable to a cyberthreat dubbed Krøøk that can intercept and decrypt Wi-Fi traffic using WPA2 connections.

ESET researchers said the vulnerability affects devices containing some of the most common Wi-Fi chips. This includes those from Broadcom and Cypress, whose vendor partners range from Amazon and Apple to Samsung and Asus, among others.

While many of these firms have already released patches, the risk of Krøøk spans both WPA2-Personal and WPA2-Enterprise protocols, according to the study.

How Krøøk Works

Traffic that travels through these kinds of Wi-Fi packets are normally considered secure, but researchers said the vulnerability takes advantage of disassociation, a term that describes the moment when a connection is interrupted. This could be due to a low Wi-Fi signal, for example.

In many cases, devices may encounter disassociation fairly often as people move from one Wi-Fi hotspot to another, but are configured to automatically reconnect quickly to known networks. Hackers could use Krøøk to prolong these periods and then receive Wi-Fi packets that they can decrypt using the all-zero key.

That said, cybercriminals would not be able to use the vulnerability to launch botnet attacks unless they are within close physical proximity to their victims, according to the research.

Other limitations include the fact that if the original communications were encrypted, that encryption would not be broken — only the Wi-Fi channel would be compromised. Victims would also likely detect suspicious activity on the Wi-Fi network if large communication streams were intercepted.

Close the Door on Krøøk

In order to protect against Krøøk, check for patches or software updates relating to the vulnerability, which has been given the unique ID CVE-2019-15126. Firmware updates may also be necessary in some cases, researchers added.

Next, by ensuring devices are using a more advanced security protocol such as AES-CCMP encryption, both consumers and businesses should be out of danger. Better yet, explore how a security intelligence platform can monitor and help address other kinds of Wi-Fi bugs.

More from

New cybersecurity sheets from CISA and NSA: An overview

4 min read - The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) have recently released new CSI (Cybersecurity Information) sheets aimed at providing information and guidelines to organizations on how to effectively secure their cloud environments.This new release includes a total of five CSI sheets, covering various aspects of cloud security such as threat mitigation, identity and access management, network security and more. Here's our overview of the new CSI sheets, what they address and the key takeaways from each.Implementing…

Threat intelligence to protect vulnerable communities

2 min read - Key members of civil society—including journalists, political activists and human rights advocates—have long been in the cyber crosshairs of well-resourced nation-state threat actors but have scarce resources to protect themselves from cyber threats. On May 14, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) released a High-Risk Communities Protection (HRCP) report developed through the Joint Cyber Defense Collaborative that addresses the threat to these vulnerable groups, with findings contributed by the X-Force Threat Intelligence team.Cyber criminals seek stolen credentialsThe HRCP…

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today