A Devastating New Malware Campaign Unfolds, Targeting Thousands of Home Routers Worldwide
A sophisticated malware campaign has emerged, compromising thousands of home routers globally. The attack, which began to spread in late August, has already infected an estimated 20,000 devices, with the number continuing to rise rapidly. The malware, known as “Routivus,” has been identified by cybersecurity experts at SANS ISC, who are tracking its spread and working with affected ISPs to contain the outbreak.
At the heart of this malicious campaign is a cleverly designed exploit that takes advantage of a previously unknown vulnerability in a popular firmware version used by several router manufacturers. The malware injects itself into the compromised device’s system, allowing hackers to remotely access sensitive user data and take control of the router’s settings. What’s more alarming is that Routivus has been observed using its infected hosts as a network of “zombies” to spread further, amplifying its reach and making it increasingly difficult for security teams to contain.
The affected routers are primarily used by residential customers, with several major ISPs in North America and Europe reporting cases of compromised devices. While the precise impact is still being assessed, experts warn that an infected router can compromise not only the individual’s network but also the entire neighborhood’s internet connection. With Routivus able to spread through direct connections as well as Wi-Fi networks, it poses a significant threat to home users who rely on their routers for daily online activities.
The malware’s design indicates a high level of sophistication from its creators, with a keen understanding of the inner workings of modern networking protocols. Its ability to evade detection and propagate silently across infected networks underscores the need for vigilance among home users and ISPs alike. As the situation continues to unfold, SANS ISC is urging affected parties to take immediate action by restarting their routers in “bridge mode,” effectively isolating them from the wider network until a patch or security update becomes available.
In light of this rapidly evolving threat, we urge all home users to remain vigilant and ensure that their router firmware is up-to-date. Furthermore, those with compromised devices should immediately isolate their networks as a precautionary measure, pending further instructions from their ISPs. By staying informed and taking proactive steps, individuals can minimize the risk of falling prey to this insidious malware campaign.
Source: SANS ISC — 2026-09-21