|
Cisco’s security arm, Talos, today revealed a several-month-old research on a sophisticated modular malware system dubbed “VPNFilter.” Talos says it has been working on the case with public and private sector threat intelligence partners as well as law enforcement. Although the research is still underway, due to the nature of potential threats, a decision was made by the research team to share the findings so affected parties can take the appropriate action.
“Both the scale and the capability of this operation are concerning,” says a blog post published today by the Talos team. It continues: “Working with our partners, we estimate the number of infected devices to be at least 500,000 in at least 54 countries. The known devices affected by VPNFilter are Linksys, MikroTik, NETGEAR and TP-Link networking equipment in the small and home office (SOHO) space, as well at QNAP network-attached storage (NAS) devices. No other vendors, including Cisco, have been observed as infected by VPNFilter, but our research continues. The behavior of this malware on networking equipment is particularly concerning, as components of the VPNFilter malware allows for theft of website credentials and monitoring of Modbus SCADA protocols. Lastly, the malware has a destructive capability that can render an infected device unusable, which can be triggered on individual victim machines or en masse, and has the potential of cutting off internet access for hundreds of thousands of victims worldwide.”
Update May 24, 2018: NETGEAR submitted the following statement:
NETGEAR is aware of a piece of malware called VPNFilter that might target some NETGEAR routers. According to our understanding of Cisco Talos’s investigation, this malware most likely targets existing vulnerabilities for which we have already released firmware fixes.
To protect against this possible malware, we strongly advise all NETGEAR router owners to take the following steps:
To make sure that remote management is turned off on your router:
NETGEAR is investigating and will update this advisory as more information becomes available.
Sponsored byVerisign
Sponsored byRadix
Sponsored byDNIB.com
Sponsored byWhoisXML API
Sponsored byIPv4.Global
Sponsored byVerisign
Sponsored byCSC