VPNFilter is a modular malware platform and botnet associated with attacks on internet-connected network infrastructure, particularly small-office and home-office routers and network-attached storage devices. It is widely recognized for compromising embedded Linux-based devices and for its comparatively advanced architecture among IoT malware families. Reported victim device classes include routers and QNAP NAS systems, and the malware has been noted for using those footholds to search for industrial control system environments. VPNFilter is generally characterized as a multi-stage framework designed for persistent compromise and post-exploitation on edge devices. Its operational profile includes initial access to vulnerable or exposed network appliances, persistence on compromised devices, and follow-on capability delivery through modular components. In the broader IoT threat landscape, it is commonly discussed alongside large botnet operations targeting routers and NAS infrastructure. The actor or operators behind VPNFilter are not identified in the supplied facts with high confidence, and no corroborated country attribution is directly supported here. The available information supports classifying VPNFilter primarily as an advanced botnet-oriented malware operation targeting network infrastructure and storage appliances, with indications of reconnaissance against ICS-related environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cited as an example of a large botnet that advanced threat actors can build using compromised routers/IoT devices; no specific activity in this report beyond illustrative mention.
Referenced as background advanced IoT malware that attacked routers and QNAP NAS devices and sought ICS-related follow-on opportunities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.