↧
I've just become aware that my Asus RT-AX86U which is running the latest Merlin firmware (3004.388.9) might be compromised. Potentially by TheMoon malware or Alogin. I was made aware that port 53 is open, however, I don't have any port forwards enabled for 53 so I can't see why it would be open.
This seems highly suspicious. Furthermore, it appears that I'm serving DNS because if I run dig as follows I get this result:
~$ dig +short @119.2xx.xxx.xxx google.com
142.251.221.78
That...