March 3, 2020 By Shane Schick 2 min read

Researchers estimate more than a billion devices may be vulnerable to a cyberthreat dubbed Krøøk that can intercept and decrypt Wi-Fi traffic using WPA2 connections.

ESET researchers said the vulnerability affects devices containing some of the most common Wi-Fi chips. This includes those from Broadcom and Cypress, whose vendor partners range from Amazon and Apple to Samsung and Asus, among others.

While many of these firms have already released patches, the risk of Krøøk spans both WPA2-Personal and WPA2-Enterprise protocols, according to the study.

How Krøøk Works

Traffic that travels through these kinds of Wi-Fi packets are normally considered secure, but researchers said the vulnerability takes advantage of disassociation, a term that describes the moment when a connection is interrupted. This could be due to a low Wi-Fi signal, for example.

In many cases, devices may encounter disassociation fairly often as people move from one Wi-Fi hotspot to another, but are configured to automatically reconnect quickly to known networks. Hackers could use Krøøk to prolong these periods and then receive Wi-Fi packets that they can decrypt using the all-zero key.

That said, cybercriminals would not be able to use the vulnerability to launch botnet attacks unless they are within close physical proximity to their victims, according to the research.

Other limitations include the fact that if the original communications were encrypted, that encryption would not be broken — only the Wi-Fi channel would be compromised. Victims would also likely detect suspicious activity on the Wi-Fi network if large communication streams were intercepted.

Close the Door on Krøøk

In order to protect against Krøøk, check for patches or software updates relating to the vulnerability, which has been given the unique ID CVE-2019-15126. Firmware updates may also be necessary in some cases, researchers added.

Next, by ensuring devices are using a more advanced security protocol such as AES-CCMP encryption, both consumers and businesses should be out of danger. Better yet, explore how a security intelligence platform can monitor and help address other kinds of Wi-Fi bugs.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today