Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • 200,000 MikroTik Routers hijacked for cryptocurrency mining
  • Malware

200,000 MikroTik Routers hijacked for cryptocurrency mining

Do Son August 4, 2018 2 minutes read
MikroTik Routers
Add Daily CyberSecurity as a preferred source on Google

Brazil has been attacked by a well-designed cryptocurrency attack that has infected hundreds of thousands of routers across the country. The offense is still in progress, mainly affecting the MikroTik router. In this case, more than 200,000 machines were affected, creating a vast XMR cryptocurrency mining botnet across Brazil.

The perpetrator can infect the device with malicious code and secretly run CoinHive in the background. For those unfamiliar, CoinHive is a favorite Monero mining script that has been widely used to exploit cryptographic currency to exploit cryptographic currency, which often uses for philanthropy, but unfortunately this time it is not.

This type of attack is known as a zero-day attack, exploiting previously unknown code vulnerabilities. This zero-day allows CoinHive to run on every page accessed by the exposed machine. There may be millions of websites loading these cryptocurrency computing loads every day.

According to Trustwave, “Initial investigation indicates that instead of running a malicious executable on the router itself, which is how the exploit was being used when it was first discovered, the attacker used the device’s functionality in order to inject the CoinHive script into every web page that a user visited.”

https://twitter.com/MalwareHunterBR/status/1023893755974352896

The attack began earlier this week and is believed to be in its early stages. BleepingComputer reported that it launched a second attack, bringing the total number of affected machines to more than 200,000.

Therefore, for the network administrator, it is necessary to pay particular attention to the MikroTik router used in the network, and timely check whether the router has installed the system patch in time. This is not the first time that the MikroTik router has become the target of malware. In March of this year, there was also a cybersecurity incident in which hackers spread and installed spyware on users’ computers through the loopholes of the router.

Related coverage

  • Hide’N Seek Botnet is Targeting Smart Home Devices
  • Hackers Exploit YouTube for Game Cracks, Steal Your Data
  • Sophisticated Cyber Espionage: Earth Baxia Uses CVE-2024-36401 and Cobalt Strike to Infiltrate APAC
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: MikroTik Routers

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90937CVSS 9.9
    froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect...
  • CVE-2026-90919CVSS 9.8
    LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config...
  • CVE-2026-90898CVSS 9.8
    Bifrost registers MCP clients through its management API. A stdio client is...
  • CVE-2026-90703CVSS 9.1
    A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element...
  • CVE-2026-90702CVSS 9.1
    A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the...
  • CVE-2026-90699CVSS 9.9
    A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects...
  • CVE-2026-90693CVSS 9.9
    A flaw has been found in D-Link DIR-878 120B05. This impacts the...
  • CVE-2026-90692CVSS 9.9
    A vulnerability was detected in D-Link DIR-878 120B05. This affects the function...
  • CVE-2026-82787CVSS 9.8
    Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability...
  • CVE-2026-90680CVSS 9.9
    A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.