U.S. authorities and private-sector researchers disrupted VPNFilter, a large botnet that had infected more than 500,000 small-office and home-office routers and network-attached storage devices in at least 54 countries. The Justice Department announced action against the botnet after Cisco Talos exposed the malware, and the FBI seized command-and-control infrastructure to cut off attacker access. US-CERT warned that the malware targeted network infrastructure devices from multiple vendors and urged owners to reboot, patch, and secure affected equipment.
Investigators described VPNFilter as a modular platform capable of credential theft, traffic interception, man-in-the-middle operations, Tor-based anonymization, industrial control system traffic monitoring, and rendering devices unusable. Analysis tied the campaign to APT28/Sofacy, a group associated with Russian intelligence, with code similarities and operational links reinforcing the attribution. Researchers said infection spikes in Ukraine suggested the operators may have been preparing a broader disruptive attack, but the coordinated law-enforcement and industry response interrupted the campaign before its most destructive capabilities were deployed.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
Trend Micro said it worked with Shadowserver to upgrade the VPNFilter second-stage sinkhole using a valid image so infected devices would not progress into listening mode. The article also reported that 363 networks connected back to the sinkhole and 1,801 networks initially responded positively, indicating infections likely persisted years after the 2018 disruption.
On May 23, 2018, the Justice Department announced actions to disrupt the APT28 botnet of infected routers and network storage devices. According to Talos, the FBI seized the attackers' command-and-control infrastructure, preventing commands from being broadcast to compromised devices.
Cisco Talos disclosed the VPNFilter malware campaign on May 23, 2018, describing a sophisticated operation that had infected more than 500,000 routers and network-attached devices across at least 54 countries.
Sharp spikes in VPNFilter infections were observed on May 8 and May 17, 2018, with the sudden growth occurring almost exclusively in Ukraine.
By March 2018, additional VPNFilter malware samples were found that contacted Photobucket and used toknowall.com as a backup communication channel.
By the end of August 2017, the FBI had been alerted to a home router showing unusual behavior linked to malware infection. The device attempted to connect to a Photobucket account to retrieve an image used in the malware's communications chain.
On May 4, 2017, toknowall.com was changed from a Bulgarian hosting provider to an IP address hosted in France.
A domain later identified as part of VPNFilter's command-and-control mechanism, toknowall.com, was registered in December 2015.
Analysis of reused RC4 code, including an implementation flaw matching BlackEnergy malware, helped government agencies attribute VPNFilter to APT28/Sofacy, a group associated with Russian intelligence services.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourceblog.talosintelligence.com
Open sourcejustice.gov
Open sourceus-cert.gov
Open sourceus-cert.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.