Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks
#1
Quote:Over 100,000 routers have had their DNS settings modified to redirect users to phishing pages. The redirection occurs only when users are trying to access e-banking pages for Brazilian banks.

According to Netlab experts, the hackers are scanning the Brazilian IP space for routers that use weak or no passwords, accessing the routers' settings, and replacing legitimate DNS settings with the IPs of DNS servers under their control.

This change redirects all DNS queries that pass through the compromised routers to the malicious DNS servers, which respond with incorrect info for a list of 52 sites.

https://blog.netlab.360.com/70-different...ostdns-en/

Source: https://www.zdnet.com/article/gigantic-1...ian-banks/
[-] The following 1 user says Thank You to silversurfer for this post:
  â€˘ harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
PCI Express 7.0 official specifications ...
PCI Express 7.0 sp...harlan4096 — 09:25
Google releases Android 16, now availabl...
Google has release...harlan4096 — 09:24
Google Chrome 137.0.7151.103/.104
Google Chrome 137....harlan4096 — 09:35
Thunderbird version 139.0.2 (stable rele...
Thunderbird versio...harlan4096 — 09:26
Emsisoft Anti-Malware 2025.5.0.12672
Changes in 2025.5....harlan4096 — 07:22

[-]
Birthdays
Today's Birthdays
avatar (39)Julioagopy
avatar (49)aolaupitt2558
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>