MikroTik Router SSH Unauthenticated Hijacking Campaign
First seen Sep 7, 2026 · Updated Sep 7, 2026
Attackers are actively hijacking internet-exposed MikroTik routers by abusing their SSH remote-access service to gain full administrative control without authentication. CERT Polska issued a warning on September 5, 2026, with confirmed exploitation activity dating back to at least September 2. No victim count or specific technical root cause has been publicly disclosed yet.
Technical Analysis
The attack targets MikroTik RouterOS devices with SSH management interfaces exposed directly to the internet, allowing threat actors to bypass authentication controls and obtain administrative access to the underlying router. This suggests exploitation of a misconfiguration, default credential weakness, or an undisclosed authentication-bypass flaw in the SSH service rather than a named CVE at this time. Once compromised, routers can be leveraged for traffic interception, DNS hijacking, botnet recruitment, lateral network pivoting, or as relay infrastructure for further attacks. Organizations running AI agents or LLM-based tooling behind or through compromised MikroTik routers face risk of traffic interception, credential/API key theft in transit, and man-in-the-middle manipulation of agent-to-service communications, making this agent-relevant where such routers sit on network paths used by agentic infrastructure.
Affected Systems
MikroTik routers running RouterOS with SSH management service enabled and exposed to the public internet without restriction (specific RouterOS versions not yet disclosed)
Indicators of Compromise
- No specific hashes, IPs, or domains published at time of reporting; CERT Polska warning dated September 5, 2026 references activity beginning September 2, 2026
Remediation Steps
- 1
Disable internet-facing SSH
Restrict or disable SSH access on MikroTik routers from the WAN interface; limit management access to trusted internal networks or VPN only.
- 2
Enforce strong authentication
Require key-based SSH authentication, disable password login, and change all default or weak credentials on RouterOS devices.
- 3
Apply firmware updates
Update RouterOS to the latest stable release and monitor MikroTik/CERT Polska advisories for patches addressing this issue.
- 4
Network segmentation and monitoring
Segment router management interfaces from production networks, enable logging, and monitor for unauthorized configuration changes or new admin accounts.
- 5
Firewall rule review
Audit and tighten firewall rules to ensure no unintended exposure of management ports (SSH, Winbox, API) to the internet.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.