Your management plane answered the internet with a shell and no login.

CERT Polska warned on September 5 that attackers are taking full administrative control of MikroTik routers whose SSH service sits on the public internet, and they are doing it without authenticating. Successful attacks date to at least September 2. The Hacker News reviewed the advisory on September 6 and found no victim count. That silence is normal. Mass edge takeovers rarely arrive with a neat spreadsheet of names.

This is a cybersecurity problem of skipped checks. Your firewall still passes “allowed admin.” Your endpoint still reports healthy until someone flips Defender off. Your users still have passwords while an infostealer spends their live session. The challenge you paid for never ran.

Reachable SSH Became Full Admin

If SSH is bound to a WAN address, scanners already have your admin console. CERT Polska called out MikroTik. The operational lesson applies to every router, firewall, and SD-WAN appliance that still offers SSH, a web UI, or an API on a public IP. Those boxes mint routes, DNS, VPN tunnels, and NAT. Full admin there is full admin on the path your users take to work.

MikroTik-style network router used for internet edge routing and remote administration
CERT Polska says internet-exposed MikroTik SSH is enough for unauthenticated admin takeover.

A brute-force campaign is optional when the daemon never asks who you are.

Pull the running service list, the user list, scheduled scripts, and any SOCKS, proxy, or tunnel features you did not enable. Compare firmware and config to a known-good export you keep off the device. New local users and surprise schedulers are the incident.

A WAN management port is a production identity system.

Ticket it that way.

This is a bad look for any vendor that still ships management services listening on WAN interfaces by default. Defense in depth that stops at the perimeter and treats the appliance as “just routing” collapses the moment SSH listens on a public address. Put management on a network the internet cannot route to. Require a jump host you own. Send admin logs somewhere the router cannot rewrite.

If that box can reach your jump hosts, it can become the jump host.

Host Cybersecurity Got Switched Off First

Elastic Security Labs documented four previously unreported programs tied to REVSTEALER, a Windows information stealer. The stealer deletes itself.

The helpers stay.

Elastic named ProManager, WinUpdate, SoftManager, and a fourth companion module. WinUpdate switches off Windows Update and Microsoft Defender, then runs a cryptocurrency miner. Threat detection that keys on the original stealer binary is already late. Incident response that calls the host clean because the first payload vanished leaves you with a silent miner and a dark updater.

Windows endpoint malware modules remaining after an information stealer deletes itself
REVSTEALER helpers remain after the stealer self-deletes, including a module that kills Defender and Windows Update.

You lose the endpoint in two stages. First the harvested data. Then the controls you would use to notice the rest.

Help Net Security’s weekly roundup added the cloud-side version of the same skip. Anthropic has been locking Claude users out after infostealers hijacked login sessions. The password can still be valid. The session is already someone else’s. Cyber security programs that only force a password reset leave the stolen cookie in play until the IdP or the vendor kills it.

September’s Patch Tuesday forecast is another record pile of CVEs. The hosts in these stories did not wait for your change window. One class skipped the credential check. Another class killed the updater so the next patch never installs. A third class spent a live session so the next prompt never appears.

Shrink Admin Reach Before You Hunt

Stop waiting for a prettier indicator of compromise. Do this on the network you actually run.

  • Pull SSH, vendor web UIs, and management APIs off every public address. Management belongs on a dedicated network or a named jump host.
  • Inventory MikroTik and other edge gear from an out-of-band source. Diff running config against a known-good export. Hunt new users, schedulers, unexpected tunnels, and DNS changes.
  • On Windows, prove Defender and Windows Update are running and policy-enforced. Hunt the named REVSTEALER helpers and any unexplained miner, even if the original stealer is gone.
  • Treat infostealer telemetry as a session incident. Revoke refresh tokens, force reauthentication, and rotate API keys for AI and SaaS tools.

Security hardening for appliances should match what you already do for domain controllers: named admins, no shared root, config backups that get diffed, firmware proof, and alerts when management services bind to an unexpected interface.

Threat detection should fire on Defender disablement, Windows Update service stops, and new listening ports on routers. Those signals are cheaper than a botnet sinkhole publishing your IP.

Incident response needs two playbooks you can run at 2 a.m. One for an edge device that may have been a silent admin console. One for a workstation where the stealer is gone and host defenses are off. Reimage the host. Then hunt the miner, the tunnel, and the stolen session before you close the ticket.

You still need patches and a SOC.

Close the open admin path first.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.