Security researchers have discovered a rare strain of router-rooting malware that targets network devices running either Linux or Unix.
The malware, which poses as an Executable and Linkable Format (ELF) file, carries out a brute-force attack on router user name-password pairs from compromised PCs.
If successful, the malware sets up an IRC backdoor onto compromised systems. Early tests by net security firm Trend Micro have confirmed that the malware works on routers from D-Link. Other systems may also be affected.
Strains of viruses or Trojans that attack network infrastructure components are rare but not unprecedented. For example, a 2008 attack involving DNS poisoning targeted modems in Mexico.
The attack targeted a known vulnerability in 2Wire modems, a brand issued by local ISPs to an estimated two million customers at the time, and was ultimately designed to redirect surfers from one of the largest banking website in Mexico to a counterfeit site.
More recently the so-called Chuck Norris botnet hijacked poorly-configured routers and DSL modems last year. ®