What's new

EOL ASUS routers affected by TheMoon malware

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

XIII

Very Senior Member
EOL ASUS routers affected by TheMoon malware:

 
That article contains zero information as to what devices are susceptible. An RT-N16 also counts as an EOL device, for that matter.

If the author was able to state that EOL devices are targeted, then he should be able to state actual model names, unless he is only speculating...
 
That article contains zero information as to what devices are susceptible.
I was also disappointed about that.

They did mention this:
Through Lumen’s global network visibility, Black Lotus Labs has identified the logical map of the Faceless proxy service, including a campaign that began in the first week of March 2024 that targeted over 6,000 ASUS routers in less than 72 hours.
I wonder how they measured that.
 
Speculation: TheMoon spreads via a worm component that scans for vulnerable web servers, so if Access from WAN is Off along with the other router external hardening the risk is reduced significantly. Assumes Current Firmware, Unique Username & Password, and all of this OFF: Access from WAN, Respond to Ping, Telnet, SSH, Port Forwarding, UPnP, and any other insecure setting.

See:
Also See: https://blog.lumen.com/the-darkside-of-themoon/
 
Last edited:
Yes. In the past there has been a few scaremonging articles that failed to mention that the attack vector was "brute force attack against weak passwords", which isn't really a device vulnerability, but just user stupidity...
 
Remember, this is not a "new" issue - it's getting press at the moment...

Key take-aways from this are:

1) Keep your firmware up to date
2) Don't use default passwords (and usernames if the platform allows it)
3) Keep exposed services to a minimum - most folks don't need to open any router based services to the internet
4) If your HW is EOL/EOS, it's a good thing to move on to newer hardware
 
Say what you will, but this is the kind of stuff why I'm in the process of getting rid of all Broadcom-based Asus devices (of mine, friends or clients') and switching to OpenWrt.
As long as the router has at least 8 or 16 MB of flash, there's really no such thing as EOL or lack of support with OpenWrt (even for WiFi 4, i.e. N devices).

Don't say I didn't warn you guys...
 
Which Asus routers don't support OpenWrt? The EOL RT-AC68U does. Will updated OpenWrt firmware still be produced for it...?
 
Thanks for the warning. Good luck with OpenWrt.
 
Which Asus routers don't support OpenWrt? The EOL RT-AC68U does. Will updated OpenWrt firmware still be produced for it...?
Take a closer look and you will see that most (if not all) Broadcom-based Asus routers' WiFi is NOT supported (AC68U included).
 
Wow. I just read this. This says 7000 routers per week are being added. And it is due to not fixing some vulnerability which allows them to deploy the malware.

Similar useless scare article that lacks any detailed information like the one's already posted earlier. No information on exactly how the routers are being exploited and which specific routers are affected. Just "speculation" and "other methods" like brute forcing the router password.
 
Similar useless scare article that lacks any detailed information like the one's already posted earlier. No information on exactly how the routers are being exploited and which specific routers are affected. Just "speculation" and "other methods" like brute forcing the router password.
It does not say password changes but lack of fixing their code vulnerabilities'. As I remember over past years ASUS chooses which vulnerabilities they fix. They don't just fix all of them. What it sounds like to me one of their not fixed vulnerabilities is biting them in the butt. And they do not want to spend the money to fix it. They would rather have people buy new routers as it makes them more money.
 
Fresh Tomato on my old AC88U, everything works though I did need to fiddle, reverse the port order or something as I recall. Really it was smooth though,
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top