Executive Summary
In September 2026, attackers exploited MikroTik RouterOS devices through internet-exposed SSH services, gaining full administrative control without authentication. CERT Polska reported active exploitation beginning September 2, targeting RouterOS versions 6.0.0-6.49.21, 7.0.0-7.23.4, and 7.24-7.24.2 through a vulnerability combination dubbed 'MikroTrick.' The attacks allowed unauthorized configuration changes and complete device compromise, prompting immediate security updates from MikroTik across multiple RouterOS channels. Network infrastructure attacks like this highlight the critical importance of securing remote access services and implementing proper network segmentation. The incident demonstrates how exposed management interfaces continue to be prime targets for threat actors seeking to establish persistent network footholds and lateral movement capabilities.
Why This Matters Now
This attack represents a broader trend of infrastructure-targeting campaigns where threat actors exploit internet-facing network devices to establish persistent access and conduct lateral movement across enterprise networks.
Attack Path Analysis
Attackers exploited internet-exposed SSH services on MikroTik routers to gain unauthenticated administrative access through a 2-vulnerability chain dubbed 'MikroTrick'. Once inside, attackers established persistence through unauthorized configuration changes and privileged account creation, then used the compromised routers as pivot points for network reconnaissance and lateral movement. The routers served as command and control infrastructure for broader network attacks, while attackers exfiltrated sensitive network configurations and potentially intercepted traffic flowing through the devices. Finally, the compromise enabled sustained network access and potential disruption of organizational connectivity.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited internet-exposed SSH services on vulnerable MikroTik RouterOS devices using a 2-vulnerability chain to gain unauthenticated administrative access
Related CVEs
CVE-2024-52340
CVSS 6.5A privilege escalation vulnerability in MikroTik RouterOS allows remote attackers to gain administrative access through exposed SSH services without proper authentication.
Affected Products:
MikroTik RouterOS – 6.0.0 to 6.49.20, 7.0.0 to 7.23.3, 7.24.0 to 7.24.1
Exploit Status:
exploited in the wildCVE-2024-52341
CVSS 6.5An authentication bypass vulnerability in MikroTik RouterOS SSH implementation allows remote attackers to execute commands without valid credentials when combined with CVE-2024-52340.
Affected Products:
MikroTik RouterOS – 6.0.0 to 6.49.20, 7.0.0 to 7.23.3, 7.24.0 to 7.24.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Remote Services: SSH
Impair Defenses: Disable or Modify System Firewall
Create Account: Local Account
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Data from Local System
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – System Security Parameters Configuration
Control ID: 2.2.6
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Identification and Classification of Critical Assets
Control ID: Article 8
CISA ZTMM 2.0 – Network Segmentation and Micro-segmentation
Control ID: Network/Environment Pillar
NIS2 Directive – Risk Analysis and Information System Security Policies
Control ID: Article 21.2(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
MikroTik router compromises directly threaten network infrastructure backbone, enabling lateral movement and unencrypted traffic interception across telecommunications infrastructure.
Internet
SSH authentication bypass in MikroTik routers compromises ISP and hosting infrastructure, allowing command control establishment and egress traffic manipulation.
Financial Services
Network infrastructure compromise violates PCI DSS compliance requirements, exposing encrypted financial data transmission and enabling east-west traffic monitoring.
Health Care / Life Sciences
Router hijacking breaches HIPAA encryption requirements for data in transit, compromising patient data through unencrypted traffic exposure and segmentation failures.
Sources
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authenticationhttps://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.htmlVerified
- Vulnerabilities in MikroTik RouterOS actively exploitedhttps://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/Verified
- MikroTik RouterOS September 2026 Security Updatehttps://mikrotik.com/supportsec/september-2026-vulnerability/Verified
- RouterOS 7.23.5 Long-term Releasehttps://forum.mikrotik.com/t/7-23-5-long-term-is-released/272867Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have reduced the blast radius of this MikroTik router compromise by constraining lateral movement and limiting the attackers' ability to pivot through network segments for reconnaissance and data exfiltration.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native workloads would likely have remained isolated from the compromised router infrastructure, reducing the scope of systems accessible to attackers through segmented network boundaries.
Control: Zero Trust Segmentation
Mitigation: Administrative privilege scope would likely have been constrained to specific network segments, reducing the attackers' ability to leverage router credentials for accessing segmented cloud workloads and resources.
Control: East-West Traffic Security
Mitigation: Lateral movement pathways would likely have been significantly constrained through microsegmentation, limiting attackers' ability to pivot from router infrastructure into cloud workloads and application environments.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely have been detected and constrained through comprehensive traffic analysis, reducing the attackers' ability to maintain persistent channels across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely have been constrained through controlled egress policies, limiting the attackers' ability to extract sensitive information from segmented cloud workloads and applications.
Organizational impact would likely have been constrained to network connectivity disruption, with cloud-native applications and workloads remaining protected from the router-based compromise through Zero Trust isolation.
Impact at a Glance
Affected Business Functions
- Network Infrastructure Management
- Remote Access Services
- Internet Connectivity
- Network Security Controls
Estimated downtime: 3 days
Estimated loss: N/A
Network configuration data, administrative credentials, routing tables, and potential lateral movement access to internal network segments through compromised router infrastructure
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent compromised network infrastructure from serving as lateral movement pivot points
- • Deploy Multicloud Visibility & Control to detect anomalous network device behaviors and unauthorized configuration changes
- • Enforce Egress Security & Policy Enforcement to prevent data exfiltration through compromised network infrastructure
- • Utilize Threat Detection & Anomaly Response capabilities to baseline network device behavior and alert on suspicious administrative activities
- • Apply Cloud Native Security Fabric inline enforcement to inspect and control traffic flowing through potentially compromised network segments



