Attackers Seize MikroTik Routers via SSH, Hitting RouterOS 6.49.21 and 7.23.4 Users
Updated
Updated · The Hacker News · Sep 6
Attackers Seize MikroTik Routers via SSH, Hitting RouterOS 6.49.21 and 7.23.4 Users
3 articles · Updated · The Hacker News · Sep 6
Summary
CERT Polska said attackers have been exploiting internet-exposed MikroTik SSH since at least Sept. 2 to gain full administrative control without authentication.
MikroTik issued fixes for RouterOS versions below 6.49.21, 7.23.4 and 7.24.2, while long-term users are told to install 7.23.5 because it keeps the security patch and fixes a DHCP regression.
Until patching is complete, CERT urged admins to disable or restrict exposed management services—especially SSH, WWW/WWW-SSL and bandwidth-test—and avoid starting TLS or built-in SSH client sessions from unpatched devices.
Compromise checks include RouterOS Flagged status, unknown users or scripts, unusually privileged ops accounts and logs showing ssh:-2@; suspected devices should be isolated, preserved, factory-reset and rebuilt from trusted configurations.
CERT calls the two-flaw chain 'MikroTrick,' but neither it nor MikroTik has identified the exact vulnerabilities or confirmed whether the attacks were true zero-days.