VPNFilter
Sign in to saveAlso known as worm
VPNFilter is malware designed to infect routers and certain network attached storage devices. It is estimated to have infected approximately 500,000 routers worldwide at its peak, though the number of at-risk devices is larger. It can steal data, contains a "kill switch" designed to disable the infected router on command, and is able to persist should the user reboot the router. The FBI believes that it was created by the Russian Fancy Bear group. In February 2022, the CISA announced that a new malware called Cyclops Blink produced by Sandworm had replaced VPNFilter.
In the Vinony graph
Within Vinony's link graph, VPNFilter is referenced by 240 other articles, and connects out to Federal Bureau of Investigation, 2013 South Korea cyber attack and Ukraine.
It is catalogued under topics including 2010s in hacking, 2018 in computing and Exploit-based worms.
Its subject is documented across 9 Wikipedia language editions.
~6 min read
Encyclopedic overview
8 sectionsContents
- Operation
- Mitigation
- Devices at risk
- Epidemiology
- FBI investigation
- FBI recommendation on removing the infection
- Notes
- References
VPNFilter is malware designed to infect routers and certain network attached storage devices. It is estimated to have infected approximately 500,000 routers worldwide at its peak, though the number of at-risk devices is larger. It can steal data, contains a "kill switch" designed to disable the infected router on command, and is able to persist should the user reboot the router. The FBI believes that it was created by the Russian Fancy Bear group. In February 2022, the CISA announced that a new malware called Cyclops Blink produced by Sandworm had replaced VPNFilter.
==Operation==
Excerpted from Wikipedia’s “VPNFilter” article, available under the CC BY-SA 4.0 licence.