The FBI advised consumers and small businesses to reboot internet routers after malware targeting network devices raised concerns that compromised hardware could be used for broader malicious activity. The guidance was aimed at disrupting infections affecting home and small-office routers, which can be abused for traffic redirection, credential theft, botnet operations, and persistent access to connected networks.
Security reporting noted that a reboot may temporarily interrupt some malware operations, but it is not a complete remediation step on its own. Users were urged to follow up by updating router firmware, changing default or exposed administrative credentials, disabling remote management where unnecessary, and replacing unsupported devices that no longer receive security patches.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
ESET published an article explaining the FBI's recommendation to reboot routers, discussing why the advice was given and what users should do. The piece helped contextualize the ongoing response to the router malware threat.
Reporting on VPNFilter mitigation clarified that rebooting a router only disrupts non-persistent stages of the malware, while Stage 1 remains installed. Users were advised to perform a factory reset, update firmware, change default passwords, and disable remote administration to fully remediate affected devices.
The FBI issued public guidance urging people to reboot their routers as part of its response to a router-focused cyber threat. The recommendation was aimed at disrupting malicious activity affecting home and small-office networking devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.