logo

Everybody reboot! VPNFilter Malware infects 500k Routers

ID: 7f0b8554-a03b-55f5-a7dd-ff977bc1ce46

STIX ID: report--7f0b8554-a03b-55f5-a7dd-ff977bc1ce46

Feed Name: Security Ledger

Threat Score
85/100

Date Published: 2018-05-24

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Cisco Talos disclosed a widespread malware campaign called VPNFilter that has infected roughly half a million routers and NAS devices across dozens of countries; the malware is persistent, can exfiltrate credentials and monitor industrial Modbus traffic, and includes a destructive 'kill' command that can brick devices, with spikes observed in Ukraine and overlap noted with ICS-focused BlackEnergy activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.