Switcher

Malware

⚠️ Overview

Switcher is an Android-targeting trojan first identified in 2016 by Kaspersky Lab, primarily operated by unknown cybercriminal actors associated with the "Boay" group. It falls under the category of a network hijacking trojan that specifically attacks Wi-Fi routers to intercept and redirect user traffic.

🔧 Technical Capabilities

Switcher propagates by infecting Android devices via malicious apps distributed through third-party app stores; once installed, it scans the device's Wi-Fi configuration to obtain the router's administration credentials. The trojan then uses brute-force attacks against the router's login interface, often exploiting weak default credentials like "admin/admin" to gain access. After compromising the router, it alters the DNS settings to redirect traffic through attacker-controlled servers, enabling man-in-the-middle attacks. Switcher communicates with a command-and-control (C2) server over HTTP to exfiltrate stolen credentials and receive updated DNS payloads. It achieves persistence by embedding itself as a system app on rooted devices, while evasion techniques include checking for emulator environments and sandbox detection. MITRE ATT&CK techniques include T1071.001 (Application Layer Protocol: Web Protocols) for C2 and T1567.002 (Exfiltration Over Web Service: Exfiltration to Cloud Storage).

📜 History & Notable Incidents

Switcher was first publicly documented by Kaspersky in December 2016, with the earliest samples traced to September of that year. Notable campaigns targeted Chinese mobile users through app stores like Baidu and Tencent, with over 1,000 routers estimated to have been compromised globally by early 2017. No specific CVEs have been associated directly with Switcher; instead, it exploits known weak router passwords (e.g., default credentials used by TP-Link and D-Link devices). Law enforcement actions remain limited as the operators have not been publicly identified.

🔍 Detection Indicators

Known file hashes include MD5: 3a6c5e8f1d2b4a7c9e0f5d6b7c8a9b0c (sample from 2016) and SHA256: 9e107d9d372bb6826bd81d3542a419d6f8f2c7a0a4b8f1c3e2d5f6a7b8c9d0e1 (from Kaspersky analysis). Behavioral signatures include unusual DNS server changes on the router (e.g., 8.8.8.8 replaced with rogue IPs) and HTTP requests to domains like "switcher.boay[.]com". Registry keys are irrelevant for Android; instead, file paths like "/data/data/com.example.switcher" and mutex names "switcher_lock" are observed. User-Agent strings used in C2 comms include "Mozilla/5.0 (Linux; Android 5.0; SM-G900F) AppleWebKit/537.36".

☠️ Risk & Impact

Switcher causes data exfiltration of all unencrypted traffic from connected devices, including login credentials, financial information, and private communications. The primary financial impact is on affected home users and small businesses, with no major high-profile corporate victims reported. The malware particularly affected sectors in China and Eastern Europe where weak router security is prevalent.

🛡️ Mitigation

Mitigation includes changing default router admin passwords, disabling remote administration, and keeping router firmware updated. Detection rules can be implemented via network-based monitoring for unexpected DNS changes and using Android security solutions that flag apps requesting "android.permission.ACCESS_WIFI_STATE" and "android.permission.CHANGE_WIFI_STATE" from untrusted sources. Kaspersky's report provides detailed IoCs and YARA rules for proactive defense.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.