Forum Moderators: open

Message Too Old, No Replies

VPNFilter Malware Has Killswitch For Routers

         

engine

7:15 pm on May 24, 2018 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



According to Cisco's Talos Intelligence Group, there's a malware, they've dubbed VPNFilter, that has infected more than 500,000 routers in 54 countries.
The malware, which the security researchers are calling VPNFilter, contains a killswitch for routers, can steal logins and passwords, and can monitor industrial control systems. VPNFilter Malware Has Killswitch For Routers [cnet.com]
"Quite anything is possible, this attack basically sets up a hidden network to allow an actor to attack the world from a stance that makes attribution quite difficult," Craig Williams, Talos' director, said in an email.


As with any of these things, it's possibly out-of-date firmware that's causing the problems, but the researchers indicate the following makes are affected: Linksys, MikroTik, Netgear and TP-Link.

keyplyr

1:17 am on May 25, 2018 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Looks like I'm safe, at least for the present.

At work I've got Qualcomm's 5g with WiFi Certified and at home I just picked up the latest Motorola 20 channel quad-band.

I once used Linksys and Netgear. They worked as intended but that was long before the high-end demand/capabilities of routers nowadays.

engine

11:15 am on May 25, 2018 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



I asked a few friends last evening when they last updated their router firmware. All said they never have. One asked if it was even a thing.

It's probably the forgotten hardware.

aristotle

7:11 pm on May 25, 2018 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Looks like the U.S. FBI has shut down the master server:

FBI seizes domain Russia allegedly used to infect 500,000 consumer routers[arstechnica.com ]

keyplyr

7:15 pm on May 25, 2018 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



That's true engine... and most routers don't run anti virus/malware getting updates.

Both my routers are higher-end so they have lots of controls on their web facing account pages, but once installed & preferences set, I've never gone back to maintain them... my bad.

For a few years now I've been reading about hacks targeted at routers. They're the target noone watches and I've read that many botnets are run from ISP customer's routers undetected.

engine

4:06 pm on May 30, 2018 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Interestingly, the FBI issued a PSA for users to reboot their routers with the aim of disrupting the malware. It goes on the recommend updating the firmware.

[ic3.gov...]