Categories: Security News

NewsCriminals Exploit Six-Year-Old Vulnerability to Infect Zyxel Routers with Malware for Botnet Activities

Malicious actors are attempting to compromise routers manufactured by Zyxel using a vulnerability dating back six years to install malware and incorporate the compromised devices into a botnet for executing distributed denial-of-service (DDoS) attacks. The targeted router model is the Zyxel P660HN-T1A, which has reached end-of-life since 2016 and no longer receives security updates.

The vulnerability (CVE-2017-18368) in the router allows unauthorized attackers to execute commands on the device. Despite the router’s lack of support since 2016, Zyxel’s latest firmware release still addresses the security flaw. However, attackers have been trying to infect vulnerable routers with the Gafgyt malware for several years, an issue that Zyxel themselves warned about in 2019.

Earlier this week, Fortinet reported ongoing attacks exploiting this vulnerability. In response, the Cybersecurity and Infrastructure Security Agency (CISA) of the US Department of Homeland Security issued a warning, urging federal government agencies to install firmware version 3.40(BYF.11). Following CISA’s alert, Zyxel stated users, reiterating that the P660HN-T1A is a legacy product that is no longer supported and should be replaced with new equipment.

Max Reisler

Greetings! I'm Max, part of our malware removal team. Our mission is to stay vigilant against evolving malware threats. Through our blog, we keep you updated on the latest malware and computer virus dangers, equipping you with the tools to safeguard your devices. Your support in spreading this valuable information across social media is invaluable in our collective effort to protect others.

Recent Posts

Remove Gaming-news-tab.com browser hijacker virus

Upon closer inspection, Gaming-news-tab.com is more than just a browser tool. It's actually a browser…

15 hours ago

Remove Finditfasts.com browser hijacker virus

Upon closer inspection, Finditfasts.com is more than just a browser tool. It's actually a browser…

15 hours ago

Remove Hotsearch.io browser hijacker virus

Upon closer inspection, Hotsearch.io is more than just a browser tool. It's actually a browser…

2 days ago

Remove Laxsearch.com browser hijacker virus

Upon closer inspection, Laxsearch.com is more than just a browser tool. It's actually a browser…

2 days ago

Remove VEPI ransomware (Decrypt VEPI files)

Every passing day makes ransomware attacks more normal. They create havoc and demand a monetary…

3 days ago

Remove VEHU ransomware (Decrypt VEHU files)

Every passing day makes ransomware attacks more normal. They create havoc and demand a monetary…

3 days ago