Your Asus router may require an urgent update to protect against sticky botnet – PC Gamer

0
521

PC Gamer is supported by its audience. When you buy through links on our site, we may earn an affiliate commission. Learn more
By published
Update your firmware to better protect against the Cyclops Blink malware going around.
Asus has issued a warning to owners of some of its routers asking them to download a recent firmware update to help protect against new malware targeting its products. Asus recommends measures be taken immediately to prevent your network being infected with the botnet malware, known as Cyclops Blink, though is investigating a more permanent fix.
In a security bulletin on the Asus website, the company outlines the best way for users to strengthen their defences against Cyclops Blink. These include: resetting the device to factory default settings, updating the device to the latest firmware version, changing the admin password, and disabling Remote Management (should be disabled by default).
The affected Asus products are: 
The products noted as GT are seriously beefy gaming routers, and some of the RT ones are pretty chunky routers, too.
Cyclops Blink is a persistent advanced modular botnet that is tough to shake off once it has a hold on your system. Trend Micro has performed a deep-dive into the malware and exactly how it operates, which I recommend you give a read if you’re into this sort of stuff—it is fascinating to know thy enemy. Essentially, though, it sets up a route of communication between an infected device and the attacker’s servers, and is able to cipher and send data to these servers as it pleases.
In the case of the exact Asus variant of these malware, it can actually access a device’s flash memory. That means it will have pretty much unfettered access to a machine once infected. It also means that the malware can actually survive factory resets. Though as Asus notes, flashing a device should finally be rid of the malware, but how often do most users flash their entire routers?
The malware itself is modular in nature, so it’s assumed that it could be modified by its creators to run on other brands of routers relatively easily.
The botnet is reportedly linked to the Sandstorm or Voodoo Bear advanced persistent threat (APT) groups, says Trend Micro. Those groups have quite a track history: The Sandworm APT group has been linked to the VPNFilter botnet and attacks on the Ukrainian electrical grid, French presidential campaign, and the Winter Olympic games.Best chair for gaming: the top gaming chairs around
Best gaming desk: the ultimate PC podiums
Best PC controller: sit back, relax, and get your game on
The FBI, CISA, US Department of Justice, and UK National Cyber Security Centre all jointly warned about the threat of Cyclops Blink last month.
«The malicious cyber actor known as Sandworm or Voodoo Bear is using new malware, referred to as Cyclops Blink,» the joint statement reads (via The Register). Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, which exploited network devices, primarily small office/home office routers and network-attached storage devices.»
This sounds like a malware you don’t want to meddle with. As ever, updating your PC’s drivers to the latest is the best form of defence in most cases—short of disconnecting your whole PC from the internet, of course. However, I do believe there are sure to be many routers that haven’t seen a patch in their life, and that’s why it’s really important that users with those affected devices heed this call.
Jacob earned his first byline writing for his own tech blog from his hometown in Wales in 2017. From there, he graduated to professionally breaking things at PCGamesN, where he would later win command of the kit cupboard as hardware editor. Nowadays, as senior hardware editor at PC Gamer, he spends his days reporting on the latest developments in the technology and gaming industry. When he’s not writing about GPUs and CPUs, you’ll find him trying to get as far away from the modern world as possible by wild camping.
Sign up to get the best content of the week, and great gaming deals, as picked by the editors.
Thank you for signing up to PC Gamer. You will receive a verification email shortly.
There was a problem. Please refresh the page and try again.
PC Gamer is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

source