Cisco Talos and subsequent government advisories reported that VPNFilter compromised at least 500,000 small-office/home-office routers and QNAP NAS devices across 54 countries, using a modular malware framework linked by researchers to infrastructure and code patterns associated with earlier Ukraine-focused activity. The campaign targeted older devices from vendors including Linksys, MikroTik, Netgear, TP-Link, and QNAP, likely through known public vulnerabilities and default credentials rather than zero-days, and showed notable concentration in Ukraine alongside scanning on ports 23, 80, 2000, and 8080.
VPNFilter operates in multiple stages: a persistent Stage 1 loader that survives reboot and locates command-and-control infrastructure, a Stage 2 payload that enables command execution, file collection, traffic interception, data exfiltration, and device destruction, and Stage 3 plugins that add capabilities such as packet sniffing and covert communications over Tor. Researchers warned that the malware could manipulate browsing sessions and permanently disable devices by overwriting firmware and rebooting them, prompting recommendations to factory reset and reboot affected devices, patch firmware, change default credentials, and disable remote management to remove non-persistent components and reduce the risk of destructive action.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Talos reported another substantial increase in newly acquired VPNFilter victims focused in Ukraine on May 17. The activity reinforced Talos's assessment that Ukraine was a major focus of the campaign.
Talos observed a sharp spike in newly infected VPNFilter victims on May 8, with almost all of the new victims located in Ukraine. Many of the Ukrainian infections used a separate Stage 2 command-and-control infrastructure.
Cisco Talos said the VPNFilter malware framework had been quietly growing since at least 2016, targeting SOHO networking equipment and QNAP NAS devices. Talos assessed the malware as likely operated by a state-sponsored or state-affiliated actor.
Cisco Talos publicly reported the VPNFilter malware framework, estimating at least 500,000 infected devices across at least 54 countries. Talos described its multi-stage architecture, espionage and destructive capabilities, code overlap with BlackEnergy, and released detection signatures and mitigation guidance.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 41 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.