Skip to content
June 23, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • 200,000 MikroTik Routers hijacked for cryptocurrency mining
  • Malware

200,000 MikroTik Routers hijacked for cryptocurrency mining

Do Son August 4, 2018 2 minutes read
MikroTik Routers
Add as a preferred
source on Google

Brazil has been attacked by a well-designed cryptocurrency attack that has infected hundreds of thousands of routers across the country. The offense is still in progress, mainly affecting the MikroTik router. In this case, more than 200,000 machines were affected, creating a vast XMR cryptocurrency mining botnet across Brazil.

The perpetrator can infect the device with malicious code and secretly run CoinHive in the background. For those unfamiliar, CoinHive is a favorite Monero mining script that has been widely used to exploit cryptographic currency to exploit cryptographic currency, which often uses for philanthropy, but unfortunately this time it is not.

This type of attack is known as a zero-day attack, exploiting previously unknown code vulnerabilities. This zero-day allows CoinHive to run on every page accessed by the exposed machine. There may be millions of websites loading these cryptocurrency computing loads every day.

According to Trustwave, “Initial investigation indicates that instead of running a malicious executable on the router itself, which is how the exploit was being used when it was first discovered, the attacker used the device’s functionality in order to inject the CoinHive script into every web page that a user visited.”

https://twitter.com/MalwareHunterBR/status/1023893755974352896

The attack began earlier this week and is believed to be in its early stages. BleepingComputer reported that it launched a second attack, bringing the total number of affected machines to more than 200,000.

Therefore, for the network administrator, it is necessary to pay particular attention to the MikroTik router used in the network, and timely check whether the router has installed the system patch in time. This is not the first time that the MikroTik router has become the target of malware. In March of this year, there was also a cybersecurity incident in which hackers spread and installed spyware on users’ computers through the loopholes of the router.

Related coverage

  • Massive npm Dependency Confusion Attack Infiltrates Corporate Ecosystems
  • Legacy Malware Resurfaces: DarkComet RAT Uses Bitcoin Wallet Lure to Deploy UPX-Packed Payload
  • The “JobStealer” Trojan Hijacking Crypto Wallets via Fake Meetings
  • XCSSET macOS Malware Evolves: New Variant Targets Firefox, Hijacks Clipboard for Crypto Theft
  • Qwizzserial: Telegram-Driven Android SMS Stealer Infects 100,000 Devices

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: MikroTik Routers

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-46495
    ## Summary **Description** A Deserialization of Untrusted Data (CWE-502) issue in OpenDJ's...
  • CVE-2026-56348CVSS 9.1
    n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options...
  • CVE-2026-46488
    ### Summary An authentication bypass vulnerability exists due to improper trust in...
  • CVE-2026-44203CVSS 9.3
    ### Summary The OAuth 2.0 / OpenID Connect authorization endpoint does not...
  • CVE-2026-44179CVSS 9.9
    ### Summary The excerpt-include macro does not properly escape the title of...
  • CVE-2026-10789CVSS 9.6
    A maliciously crafted webpage, when visited by a user with Autodesk Fusion...
  • CVE-2026-33646CVSS 9.6
    ## Summary Mise processes `.tool-versions` files through the Tera template engine during...
  • CVE-2026-7664CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access...
  • CVE-2026-28381CVSS 9.6
    The Snowflake datasource allows for GET/PUT commands, which can allow any user...
  • CVE-2026-10561CVSS 10.0
    IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an...
Powered by CVE WATCHTOWER

🚨 Active Exploits in the Wild

  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-10735
    Multiple plugins by ShapedPlugin contain a backdoor in various versions. This makes it possible for unauthenticated attackers to...
  • CVE-2026-20262CVSS 6.5
    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,...
  • CVE-2026-54420CVSS 8.5
    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a...
  • CVE-2026-53435CVSS 8.8
    In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize...
  • CVE-2026-10795CVSS 8.1
    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions...
  • CVE-2026-11645
    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker...
  • CVE-2026-50751CVSS 9.3
    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows...
  • CVE-2026-20245CVSS 7.8
    A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local...
Powered by CVE Watchtower

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.