What is ‘evil twin’ and why care about it?

Cyber criminals are extremely inventive these days. Every time their fraudulent intent is disclosed, they find a new solution to accomplish their plan. This time, we will go into the matter of a rogue wireless access point, a strong tool for snoopers and attackers to steal sensitive information. It is one of the main concerns for people, who are constantly using public or open Wi-Fi hotspots.

What is a rogue access point?

free-wifi(1) A rogue access point (AP), or an “evil twin”, is an unauthorized Wi-Fi hotspot that is installed on a legitimate wireless local area network (WLAN). It is a wireless version of a phishing fraud. Mostly, a rogue AP does not correspond to WLAN security policy and allows any Wi-Fi device to connect to the network. It works like a bridge, letting anyone gain control over your data within minutes.

The thing is that it is very easy for adversaries to establish a rogue AP. They need only a laptop and a Wi-Fi dongle. Such invasion poses a significant risk to your personal information, as it is a core target for snoopers. They break into your network to destroy, modify, or steal your valuable data. With an “evil twin” attackers are able to monitor your traffic, and use it to infect your device with a malware or a keylogger.

How does it work?

Black hat hackers even do not need to be inside the building to install a rogue AP. They are able to attack remotely, for example, from a reception area or a car park.

After installing, a rogue AP broadcasts a signal to a local area network, causing users to lose connection. Then an “evil twin” transmits a stronger signal to overpower a regular Wi-Fi hotspot. As a result, users’ devices associate the malicious network with a legitimate wireless hotspot connection and reconnect to it. Now, all types of data, from images to passwords to financial information, are available for attackers to snoop.


