Attackers are actively hijacking MikroTik routers around the world. They exploit the router’s Secure Shell (SSH) remote-access service when it faces the internet. Alarmingly, this lets them gain full administrative control without any authentication. Poland’s cybersecurity agency, CERT Polska, issued the warning on September 5.
The attacks are already underway and confirmed. According to CERT Polska, successful intrusions date back to at least September 2. However, the agency has not disclosed how many victims exist. Additionally, the identity of the attackers remains unknown for now.
CERT Polska named the attack technique “MikroTrick.” It reportedly combines two separate flaws into one chain. Together, these vulnerabilities grant attackers complete administrative access. However, the agency did not specify exactly which two flaws combine. It also left the zero-day status of the attack unverified.
MikroTik has already released security updates to address the problem. The company published fixed RouterOS releases across multiple versions. For RouterOS 6, the fix arrives in version 6.49.21. Meanwhile, RouterOS 7 users should update to version 7.23.4 or later. CERT Polska strongly recommends installing these patches immediately.
Notably, home users may face lower risk here. MikroTik explained that home devices block public access to management ports. This protection holds as long as default firewall rules remain intact. However, manually exposed services still create dangerous openings.
Until patching is possible, CERT Polska suggests temporary protective steps. Users should disable exposed services or restrict them to trusted networks. This applies particularly to SSH, WWW, and bandwidth-test services. Additionally, users should avoid using built-in SSH clients from unpatched devices.
As the CERT puts it:
We are publishing this information on an accelerated schedule because the patched RouterOS packages are already public, and their comparative analysis has allowed the community to reconstruct some of the fixed bugs. We limit the description to the information administrators need and do not publish exploit code or details that would make automating attacks easier.
After updating, administrators must check for signs of compromise carefully. CERT Polska advises inspecting logs for unexpected privileged accounts. Account-creation logs containing “ssh:-2@” signal likely intrusion. If compromise appears, users should isolate the router first. They must then preserve evidence before resetting and rebuilding from a trusted configuration entirely.
