November 5, 2019 By Shane Schick 2 min read

Small office and home users who don’t want to see their wireless routers exploited need to watch out for a variant of the Gyfgyt malware that is leaving tens of thousands vulnerable, according to security researchers.

Gafgyt, also known as Bashlite, has been active for at least five years and has been updated to target devices from several different vendors, Palo Alto Networks’ Unit 42 noted. This includes the RealTek RTL81XX and HG532 from Huawei, as well as the Zyxel P6660HN-T1A.

Wireless routers exploited by the malware can become part of botnets that are used by cybercriminals to sell distributed denial-of-service (DDoS) attacks as a service, the researchers said.

How Gafgyt Gets In

Unfortunately, this may not be the only malware taking aim at those router models. In fact, researchers suggested Gafgyt may be waging a sort of turf war and attempting to kill off a rival strain, known as JenX, though the latter is only focused on units from RealTek and Huawei.

Gafgyt works by looking for wireless routers that are connected to an open network via the device’s scanner function, according to the report. Once it has compromised a router, it looks for JenX and, if found, replaces it. This ensures it has sole access to the compute resources that would be used in launching DDoS attacks.

Though Gafgyt is not a new threat, researchers noted that this update seems to be focusing on wireless routers connected to gaming servers, particularly private servers hosted by those using titles running the Valve Source engine, such as Team Fortress 2 and Counter-Strike.

How to Avoid Having Your Wireless Routers Exploited

Of course, wireless routers aren’t just used for gaming and, in some cases, may connect directly to enterprise networks by remote workers or those getting caught up from home.

This means organizations can avoid having their wireless routers exploited by looking for new devices (all the models being targeted have been in market for five years) and applying the same strong password protection and patch management that would be typical within a business setting.

In the worst-case scenario, organizations can fend off DDoS attacks through third parties and advanced solutions that make innovative use of artificial intelligence technologies.

More from

How prepared are you for your first Gen AI disruption?

5 min read - Generative artificial intelligence (Gen AI) and its use by businesses to enhance operations and profits are the focus of innovation in virtually every sector and industry. Gartner predicts that global spending on AI software will surge from $124 billion in 2022 to $297 billion by 2027. Businesses are upskilling their teams and hiring costly experts to implement new use cases, new ways to leverage data and new ways to use open-source tooling and resources. What they have failed to look…

Cybersecurity crisis communication: What to do

4 min read - Cybersecurity experts tell organizations that the question is not if they will become the target of a cyberattack but when. Often, the focus of response preparedness is on the technical aspects — how to stop the breach from continuing, recovering data and getting the business back online. While these tasks are critical, many organizations overlook a key part of response preparedness: crisis communication.Because a brand’s reputation often takes a significant hit, a cyberattack can significantly affect the company’s future success…

Brands are changing cybersecurity strategies due to AI threats

3 min read -  Over the past 18 months, AI has changed how we do many things in our work and professional lives — from helping us write emails to affecting how we approach cybersecurity. A recent Voice of SecOps 2024 study found that AI was a huge reason for many shifts in cybersecurity over the past 12 months. Interestingly, AI was both the cause of new issues as well as quickly becoming a common solution for those very same challenges.The study was conducted…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today