Get Hacked Without Malware: Threat Actors Target Routers to Map Your Network

Russ Warner
,
President & COO
Calendar grid icon with the month of August 2023 displayed, showing days Sunday to Saturday.

On July 13-14, the CISA, the NSA, and the FBI teamed up with 18 international partners to issue Advisory AA26-194A. 

In it, they warned of a surge in state-sponsored cyberattacks targeting internet-facing routers. Instead of using traditional malware, groups like the Russian FSB and China-linked Salt Typhoon are exploiting weak SNMP settings and outdated firmware. Their goal is to quietly steal configuration files (like config.bkp) and map out internal networks.

Key Impacts and Sectors at Risk 

By breaking into these edge devices, hackers can steal configurations and expose a network's blueprint. This allows them to harvest credentials, exploit firmware, intercept traffic, and strategically position themselves for future sabotage. 

These attacks pose a massive threat to critical sectors, including telecom, healthcare, energy, finance, defense, and government.

How Komodo Eye Secures Your Network 

Defending against malware-free network mapping requires deep visibility and strict access controls.Komodo Eye helps organizations lock down their infrastructure in the following ways:

Firmware Governance 

Running unpatched firmware makes a network an easy target for exploitation. Komodo Eye performs continuous polling—typically every 5 minutes—to capture essential data like firmware versions. 

Using an efficient "track-changes" storage method, it only saves data when a value actually changes, making it incredibly easy to spot outdated or non-compliant firmware immediately.

Rogue Device Detection 

To map a network, attackers often connect unauthorized hardware or exploit unknown network adjacencies. Komodo Eye continuously reconciles live network states against official inventories. 

By tracking live system IDs and MAC addresses, the system instantly alerts the security team the moment an "uninvited" device joins the network, eliminating dangerous blind spots.

Exfiltration Detection 

When attackers try to steal configuration files, they inevitably leave a trail in system logs. Komodo Eye uses semantic intelligence to analyze millions of logs and catch rare events—even catching a subtle error message that might only appear four times a year across 10 million devices. 

And, Komodo Eye’s 5-year data lake and other features search by MAC address to track exactly where a rogue device is physically plugged into a network.

Config & Credential Management 

To combat configuration theft and unauthorized changes, Komodo Eye maintains immutable audit trails of all configuration modifications. 

It also features an automation tool that can generate and deploy standardized "golden" configurations directly to routers to replace risky manual setups. 

For extra defense, the platform enforces scheduled credential changes across thousands of devices at once.

Air-Gapped Security 

The best way to protect against remote state-sponsored hackers is to remove your network from the cloud entirely. 

Komodo Eye is a 100% on-premises, air-gapped platform with zero cloud dependency. Built for highly secure environments like the nuclear and defense sectors, it completely eliminates the attack pathways that hackers typically use to exploit cloud-based systems.