logo

Cisco Talos: VPNFilter malware capable of stealing data, infecting IoT endpoints

ID: b6e2785a-c55b-5673-84a8-7a3126554c8f

STIX ID: report--b6e2785a-c55b-5673-84a8-7a3126554c8f

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2018-06-07

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Cisco Talos warns that VPNFilter, previously known to compromise hundreds of thousands of SOHO routers and NAS devices (initially ~500,000 in 54 countries), is more widespread and has gained new capabilities: stage-3 modules can inject malicious content into web traffic to deliver exploits to endpoints (MITM), enable data exfiltration, and include destructive ‘brick’ functionality. The report expands the list of affected vendors (ASUS, D-Link, Huawei, Ubiquiti, UPVEL, ZTE, Linksys, MikroTik, Netgear, TP-Link), emphasizes that the threat extends beyond the devices into networks they support, and recommends endpoint AV, patching and multi-factor authentication as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.