highOther

MikroTik Router SSH Unauthenticated Hijacking Campaign

First seen Sep 7, 2026 · Updated Sep 7, 2026

mikrotiksshrouter-compromiseinternet-exposednetwork-infrastructureunauthenticated-accesscert-polskaiot

Attackers are actively hijacking internet-exposed MikroTik routers by abusing their SSH remote-access service to gain full administrative control without authentication. CERT Polska issued a warning on September 5, 2026, with confirmed exploitation activity dating back to at least September 2. No victim count or specific technical root cause has been publicly disclosed yet.

Technical Analysis

The attack targets MikroTik RouterOS devices with SSH management interfaces exposed directly to the internet, allowing threat actors to bypass authentication controls and obtain administrative access to the underlying router. This suggests exploitation of a misconfiguration, default credential weakness, or an undisclosed authentication-bypass flaw in the SSH service rather than a named CVE at this time. Once compromised, routers can be leveraged for traffic interception, DNS hijacking, botnet recruitment, lateral network pivoting, or as relay infrastructure for further attacks. Organizations running AI agents or LLM-based tooling behind or through compromised MikroTik routers face risk of traffic interception, credential/API key theft in transit, and man-in-the-middle manipulation of agent-to-service communications, making this agent-relevant where such routers sit on network paths used by agentic infrastructure.

Affected Systems

MikroTik routers running RouterOS with SSH management service enabled and exposed to the public internet without restriction (specific RouterOS versions not yet disclosed)

Indicators of Compromise

  • No specific hashes, IPs, or domains published at time of reporting; CERT Polska warning dated September 5, 2026 references activity beginning September 2, 2026

Remediation Steps

  1. 1

    Disable internet-facing SSH

    Restrict or disable SSH access on MikroTik routers from the WAN interface; limit management access to trusted internal networks or VPN only.

  2. 2

    Enforce strong authentication

    Require key-based SSH authentication, disable password login, and change all default or weak credentials on RouterOS devices.

  3. 3

    Apply firmware updates

    Update RouterOS to the latest stable release and monitor MikroTik/CERT Polska advisories for patches addressing this issue.

  4. 4

    Network segmentation and monitoring

    Segment router management interfaces from production networks, enable logging, and monitor for unauthorized configuration changes or new admin accounts.

  5. 5

    Firewall rule review

    Audit and tighten firewall rules to ensure no unintended exposure of management ports (SSH, Winbox, API) to the internet.

Industries Most Exposed

telecommunicationsmanaged-service-providerssmall-and-medium-businesscritical-infrastructureretailhospitality

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.