Overview
- Researchers and Poland’s CERT Polska confirmed that successful attacks began on Sept 2 and included creation of a highly privileged 'ops' account and log entries showing a failed login user named "-2".
- The campaign uses a two-bug chain labeled MikroTrick that pairs CVE-2026-67276, an RSA public-key validation bypass that can let an attacker log in without a private key, with CVE-2026-86060, a crafted-username flaw that escalates an SSH session to full administrative privileges.
- MikroTik has published fixes for multiple RouterOS releases including 7.24.2, 7.23.5, 7.23.4, 7.25beta3 and 6.49.21 and CERT Polska tells operators to install those updates, disable or restrict internet-facing management services, and preserve logs before any factory reset.
- Investigators published IOCs tied to the campaign such as IPs 82.192.72[.]4 and 103.102.31[.]18 and several file hashes, and security researchers warn a public proof-of-concept could appear soon while hundreds of thousands of routers may still expose SSH to the internet.
- Because many MikroTik devices run long without updates, defenders should assume internet-reachable SSH is risky, rotate keys and passwords after remediation, avoid restoring untrusted backups, and expect ongoing forensic work to clarify the attack scope and who is responsible.