Thousands of routers manufactured by MikroTik have been compromised by malware attacking a vulnerability revealed April. The attack comes after a previous wave based on a vulnerability made public by WikiLeaks’ publication of tools from the CIA’s “Vault7″ toolkit. More than 7,500 of the devices are actively being spied on by attackers, who are forwarding full captures of their network traffic to a number of remote servers. Another attack has turned affected routers into a malicious proxy network using the SOCKS4 protocol over a very non-standard TCP port.”]

