CERT mailing list archives

VPNFilter Destructive Malware


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Wed, 23 May 2018 09:14:35 -0500

U.S. Department of Homeland Security US-CERT

National Cyber Awareness System:



VPNFilter Destructive Malware [ https://www.us-cert.gov/ncas/current-activity/2018/05/23/VPNFilter-Destructive-Malware 
] 05/23/2018 09:03 AM EDT 
Original release date: May 23, 2018

NCCIC is aware of a sophisticated modular malware system known as VPNFilter. Devices known to be affected by VPNFilter 
include Linksys, MikroTik, NETGEAR, and TP-Link networking equipment, as well as QNAP network-attached storage (NAS) 
devices. Devices compromised by VPNFilter may be vulnerable to the collection of network traffic (including website 
credentials), as well as the monitoring of Modbus supervisory control and data acquisition (SCADA) protocols.

VPNFilter has a destructive capability that can make the affected device unusable. Because the malware can be triggered 
to affect devices individually or multiple devices at once, VPNFilter has the potential to cut off internet access for 
hundreds of thousands of users.

NCCIC encourages users and administrators to review the Cisco blog post on VPNFilter [ 
https://blogs.cisco.com/security/talos/vpnfilter ] for recommendations and to ensure that their devices are updated 
with the latest patches. NCCIC will provide updated information as it becomes available.

________________________________________________________________________

This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ http://www.us-cert.gov/privacy/ ] policy.

________________________________________________________________________

A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have 
questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a 
notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () 
ncas us-cert gov to your address book. 

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ]  

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: