MikroTik Routers Compromised via Internet-Exposed SSH
Cyber attackers are compromising internet-exposed MikroTik RouterOS routers without requiring any password or valid authentication, gaining full administrative privileges on the devices.
Key Details:
The National Cyber Security Incident Response Team of Poland published an urgent security advisory on September 5, 2026. Investigations indicate that attacks exploiting this method have been actively used since at least September 2, 2026.
This vulnerability chain, dubbed "MikroTrick" by experts, operates by combining two separate flaws in the SSH service:
Session login with a forged signature is achieved by exploiting RouterOS's failure to validate the complete SSH RSA key.
Full administrative privileges are directly assigned to the session by bypassing the privilege matrix using specially formatted usernames.

Attack Indicators (Indicators of Compromise):
User creation logs in system logs containing ssh:-2@ or suspicious SSH login attempts using the username -2.
An unauthorized non-default user account named ops with elevated privileges created on the device.
RouterOS setting the system to a "Flagged" state during startup after an update due to detected suspicious configurations.
Recommended Security Measures
System administrators and network engineers should urgently take the following steps to protect MikroTik devices:
1. Urgent Software Update (Patching)
Upgrade RouterOS versions on devices immediately to secure versions containing the fix.
2. Restricting Exposed Services and SSH Access
Completely block management interfaces such as SSH (TCP/22), WWW/WWW-SSL, and Bandwidth-Test on the WAN side.
Configure access to management services to be allowed only via secure internal networks, IP whitelists, or an authorized VPN connection.
3. Threat Hunting and Configuration Review
After updating, run the /system/device-mode/print command from the command line to check whether the system has marked the device as "Flagged".
Inspect defined users with /user print, and scheduled scripts/tasks with /system script and /system scheduler. Ensure unauthorized accounts are audited.
Search external or local log records for the ssh:-2@ pattern and access attempts originating from unknown IP addresses.
4. Actions in Case of Potential Compromise
Do not restore directly from an old backup, as the backup of a potentially compromised device may contain malicious configurations.
Isolate the suspicious device from the network, and export the current configuration and log files for investigation.
Reset the device to factory settings and reconfigure it from scratch with a verified, secure setup.
Update all passwords, SSH keys, API keys, and associated secret data used on the router.
5. Centralized Logging and Monitoring
Instantly stream all RouterOS logs to an external SIEM or secure Syslog server to prevent logs from being deleted or tampered with.
Some of the measures that can be taken to protect against these types of attacks include:
RouterOS versions should be kept up to date.
Internet-facing SSH and management services should be disabled.
Management access should be restricted to VPN connections or trusted IP addresses.
Unauthorized users and suspicious accounts should be regularly reviewed.
SSH keys and administrator passwords should be periodically renewed.
Suspicious scripts and scheduled tasks should be regularly checked.
RouterOS logs should be forwarded to a centralized SIEM/Syslog system.
Suspicious access attempts and anomalous activities should be continuously monitored.
For more detailed information, please contact our experts at info@zerosecond.ae





















Comments