The Russian vulnerability and data leak intelligence service DLBI has identified a new scheme for stealing accounts on the Gosuslugi portal, social networks, and cloud services, DLBI told "Pervy Tekhnichesky". Attackers use special robot programs that scan corporate and home provider networks for open web router control panels.

If a panel is found, hackers try to guess the password using standard dictionaries. Once they gain access, they change the DNS server to their own, and all user requests from the compromised network to popular services are redirected to phishing pages.
On the fake website, the victim is asked for a login, password, and SMS code. To bypass browser warnings, fraudsters offer to install a "Ministry of Digital Development root certificate" – which is actually a malicious certificate. After its installation, the fake website becomes trusted. After obtaining the data, hackers change the victim's credentials and sell the hacked accounts on the darknet.
The new scheme is significantly more dangerous than social engineering because it operates fully automatically and remains unnoticed by the user until the data is stolen. To protect against this, the expert recommended setting a unique password for the router's web panel, disabling internet access to it if possible, and checking the device's DNS settings. As a temporary measure, Oganesyan advised using mobile devices outside the home Wi-Fi network to access important government services, although this reduces convenience.
Комментарии