Particle.news

MikroTik Routers Hijacked Through SSH Flaw Chain Called MikroTrick

Security teams are urging immediate patching and network restrictions to stop attacks that can give outsiders full control of exposed devices.

Overview

  • Researchers and Poland’s CERT Polska confirmed that successful attacks began on Sept 2 and included creation of a highly privileged 'ops' account and log entries showing a failed login user named "-2".
  • The campaign uses a two-bug chain labeled MikroTrick that pairs CVE-2026-67276, an RSA public-key validation bypass that can let an attacker log in without a private key, with CVE-2026-86060, a crafted-username flaw that escalates an SSH session to full administrative privileges.
  • MikroTik has published fixes for multiple RouterOS releases including 7.24.2, 7.23.5, 7.23.4, 7.25beta3 and 6.49.21 and CERT Polska tells operators to install those updates, disable or restrict internet-facing management services, and preserve logs before any factory reset.
  • Investigators published IOCs tied to the campaign such as IPs 82.192.72[.]4 and 103.102.31[.]18 and several file hashes, and security researchers warn a public proof-of-concept could appear soon while hundreds of thousands of routers may still expose SSH to the internet.
  • Because many MikroTik devices run long without updates, defenders should assume internet-reachable SSH is risky, rotate keys and passwords after remediation, avoid restoring untrusted backups, and expect ongoing forensic work to clarify the attack scope and who is responsible.