VPNFilter is a multistage, modular botnet malware framework used for espionage and destructive operations against small-office/home-office routers and network-attached storage devices. Publicly disclosed by Cisco Talos in May 2018, it compromised more than 500,000 devices across at least 54 countries, with notable infection surges in Ukraine. Targeted manufacturers included ASUS, Huawei, Linksys, MikroTik, Netgear, QNAP, TP-Link, Ubiquiti, and Upvel. The framework includes embedded Linux components and targets vulnerable network equipment. It has been linked to Russia’s GRU, including Sandworm.
VPNFilter modules intercept network traffic, collect usernames, passwords, and authorization tokens, downgrade HTTPS connections to HTTP, and manipulate routing to redirect traffic. A Modbus-monitoring module enables collection of industrial control system communications. Compromised devices can also provide an entry point for discovering and attacking other systems on connected networks. Its communication mechanisms include command-and-control information concealed in image metadata, fallback channels, and Tor-based anonymization. Destructive components, including a dedicated wiping plugin, can erase storage and render infected devices inoperable. Infections can survive device restarts, making rebooting alone insufficient for remediation. A court-authorized U.S. operation disrupted its command-and-control infrastructure in 2018, but residual infections persisted afterward. Cyclops Blink was subsequently identified as its replacement framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As explained in the advisory, the malware appeared to have emerged as early as June 2019, and was the apparent successor to another Sandworm botnet called VPNFilter, which the Department of Justice disrupted through a court-authorized operation in 2018.
As a side note, the IOCTLs used by this malware also match the ones used by the VPNFilter malware 'dstr' wiper plugin, a malicious tool attributed to Russian GRU hackers...
Cisco Talos first disclosed the existence of VPNFilter on May 23, 2018... The malware’s multi-stage modular platform supported both intelligence-collection and destructive cyber attack operations.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
both the Photobucket accounts and the toknowall.com domain were hosting images in which the IP address of the C2 server, used by the threat actor to issue instructions to the malware were hidden, disguised within the EXIF metadata of the image.
To keep important data within the malware confidential, the malicious code used encryption, implementing the RC4 encryption algorithm.
One particular module contained functionality to identify and monitor Modbus network traffic, a protocol widely used in Industrial Control Systems. | the malware could modify the routing information and create custom destinations for certain traffic; redirecting traffic from the genuine destination to a separate system under the control of the attackers.
Clearly, capturing data, especially usernames and passwords, was one goal of the attack.
One particular module contained functionality to identify and monitor Modbus network traffic, a protocol widely used in Industrial Control Systems. | the malware could modify the routing information and create custom destinations for certain traffic; redirecting traffic from the genuine destination to a separate system under the control of the attackers.
devices in over 100 countries are being scanned on ports 23, 80, 2000, and 8080, which are indicative of additional scanning for vulnerable Mikrotik and QNAP NAS devices.
By March 2018, additional malware samples were discovered that also reached out to Photobucket, and used toknowall.com as a backup in case Photobucket was unavailable.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only through a linked report illustrating the security risks of running vulnerable router firmware. The content does not describe VPNFilter's capabilities or establish that any specific OpenWrt device was infected.
Router-focused botnet/malware referenced as historical background for SOHO router compromise campaigns.
Mentioned because its stage-three 'dstr' wiper shares some IOCTL wiping-method similarities with the Acid wipers, though the report says the logic differs in detail.
A router-targeting botnet used to communicate with infected routers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.