Iran Cisco, Juniper, Fortinet and MikroTik contain malicious code

Iran accuses the US of using hidden backdoors or pre-installed botnets to disable networking equipment inside the country during recent military attacks. It claims that devices from Cisco, Juniper, Fortinet and MikroTik were knocked out at critical moments.

picture news.cn

The claim, initially promoted by Iranian state media and later by foreign media and Chinese publications, focuses on hardware failures.

According to reports from Fars and Entekhab, Tehran believes the outages indicate deep sabotage rather than ordinary technical errors.

See more articles from iGuRu.gr when you search for news on Google.

One theory is that there is malicious code in the firmware or bootloaders. Another suggests that a secret botnet was installed on the affected devices and was activated during the attacks.

This does not mean that the claim has been proven, but independent verification is nearly impossible because Iran has spent weeks significantly restricting internet access.

NetBlocks reported this week that the country’s power outage had exceeded 50 days, while Al Jazeera reported that authorities were still granting limited, tiered connectivity via “ Internet Pro ” and less restricted access with “ white SIM ” for select groups. Essentially, the power outage that Tehran is experiencing does not help to verify the accusation.

But the suppliers named by Iran have a history of security problems. NSA documents leaked by Edward Snowden in 2014 showed that the agency monitored Cisco routers during transport and installed implants before delivery.

Meanwhile, Juniper disclosed unauthorized code in ScreenOS in 2015 that could allow remote administrative access and VPN decryption.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).