VPNFilter Malware May Be Even More Dangerous Than We Thought

VPNFilter Malware May Be Even More Dangerous Than We Thought

US law enforcement revealed several weeks ago that consumer routers all over the world had been infected with dangerous malware. Owners were advised to rest the devices, but that was only a temporary fix. Now, the news is even worse. The VPNFilter malware affects more device models than previously thought, and it has a previously unknown ability that could put you at risk online.

Security researchers have traced VPNFilter back to Fancy Bear, a hacking team backed by Russian intelligence. Fancy Bear is most famous for carrying out the spear phishing attack on Clinton advisor John Podesta that yielded thousands of private emails. The team’s current operation is much less focused, though. We already knew VPNFilter affected routers from Cisco/Linksys, MikroTik, NETGEAR, and TP-Link. The new wrinkle is there are even more models and manufacturers vulnerable to VPNFilter.

According to the latest report from Cisco Talos, additional models from Linksys, MicroTik, Netgear, and TP-Link are vulnerable to VPNFilter. Plus, devices from Asus, D-Link, Upvel, Huawei, and ZTE are on the list now. There are now dozens of models and as many as 500,000 individual routers infected with VPNFilter. You can restart them to clear the actively malicious packages, but they could just come back.

US law enforcement previously warned everyone to restart their routers to clear the malware, but that only cleared the second and third stages of VPNFilter. The first stage remained active, and that’s the piece that gives the hackers access to install the active second and third stages. Routers vulnerable to VPNFilter usually run older firmware with known security holes, and many of them don’t have updates available.

Cisco was good enough to make a logo for Fancy Bear’s malware.
Cisco was good enough to make a logo for Fancy Bear’s malware.

The only sure fix is a firmware update, and most routers don’t do that automatically even if patched firmware is available. You’ll definitely want to look into that, too. An active VPNFilter infection is even more dangerous than we thought. Researchers have discovered that VPNFilter can run a man-in-the-middle attack. That allows the hackers to intercept web traffic before it gets to you and change what you see or steal sensitive data like passwords. While researchers initially thought VPNFilter was intended mainly to run attacks on larger targets, it’s beginning to look more like the users themselves are the targets.

If you have one of the devices on the latest target list, it would be a good idea to trash it and get a new router. Unfortunately, many of the infected routers will continue to operate for years to come because most consumers simply aren’t paying attention.

Continue reading

Should Spectre, Meltdown Be the Death Knell for the x86 Standard?

Spectre and Meltdown are serious CPU flaws, but do they warrant throwing out the entire closed-source CPU model?

Nvidia Goes All-In On G-Sync With New ‘BFGD’ Ultra-High-End Displays

Nvidia is bringing some of the highest-end displays imaginable to market in 2018, with 4K panels, 120Hz refresh rates, low latency displays, integrated Nvidia Shields, and support for 1,000 nits of brightness in HDR. Yowza.

Huawei’s Phone Deal With AT&T Reportedly Killed On Account of Politics

The upcoming (and unannounced) deal with AT&T to sell the new Mate 10 series was supposed to be the start of Huawei's push into North America, but the deal has reportedly fallen apart at the last minute after AT&T got cold feet, and some sources point to a political cause.

ET Deals Roundup: $200 Gift Card with Samsung 4K TV for $600, $50 Price Drop on Inspiron 15 7000, and more

Ready to upgrade to a 4K television? Maybe you're looking for a new laptop for school, or searching for the perfect camera for an upcoming vacation. Well, there are plenty of discounts floating around this week, so we've put together a list of the hottest deals. If you're looking to save big on new gear, you're bound to find something worthwhile below.