A cybercriminal group has started scanning the Internet for vulnerable Linksys routers in the first stage of an attack. The attack first compromises vulnerable routers by purportedly trying weak or default credentials. Once an attacker gains access, they hijack DNS functionality, redirecting victims to a page that attempts to convince them to download a malicious, information-stealing program known as Oski. The attacker’s page aims to harness the fear of the coronavirus pandemic to fool victims. The attackers are focused on the US and European countries.”]

