Blog | G5 Cyber Security

Switcher Android Malware Hacks TP-Link Routers, Changes DNS Settings

An Android trojan named Switcher (TrojanAndroidOS.Switcher) targets Android devices in order to take over local WiFi routers and hijack web traffic passing through them. The way this trojan works is by collecting information on the user’s WiFi network after infecting a phone or tablet. Switcher sends this information to a public C&C server, which determines ISP and decides on what DNS records to use at a later stage. Once the trojan has authenticated on a local router, it goes on to modify the router’s DNS settings.

Source: https://www.bleepingcomputer.com/news/security/switcher-android-malware-hacks-tp-link-routers-changes-dns-settings/

Exit mobile version