Skip to main content

VPNFilter Network Malware

VPNFilter is an advanced modular malware framework that has been observed targeting small and home office (SOHO) networking and network attached storage (NAS) devices throughout Europe and the USA.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

VPNFilter is an advanced modular malware framework that has been observed targeting small and home office (SOHO) networking and network attached storage (NAS) devices throughout Europe and the USA.

Threat details

It shares similarities with the BlackEnergy malware and is believed to have been created and controlled by the APT28 (Sofacy, Fancy Bear) advanced persistent threat group.

It is distributed through a multi-stage process, with the first stage being delivered to devices using publicly known exploits or default credentials. This stage, which is able to persist through reboots, will then connect with a command and control (C2) server using a number of redundant mechanisms to download the second stage. This second stage is able to exfiltrate data, execute commands and disable infected devices by overwriting critical firmware using the 'kill' or 'exec' commands. Third stage modules can also be downloaded to add further capabilities to the second stage. At present there are two known stage 3 modules; a packet sniffer for collecting network traffic and another which allows the stage 2 malware to communicate using the Tor network, although it is highly probable other modules exist.

Due to the nature of the infected devices VPNFilter will have access to all data that is transferred or stored within an affected network. The ability to disable devices can also be performed simultaneously, raising the possibility of whole networks being disabled at once. Disabled devices are likely to be unrecoverable, requiring full replacement in most cases.


Threat updates

Date Update
6 Jun 2018

Further details regarding VPNFilter have been disclosed including new third-stage modules and a larger list of targeted devices.

Ssler (or essler) is a new third-stage module able to intercept and manipulate all port 80 traffic passing through a device. It will then inject malicious JavaScript payloads in order to perform man-in-the-middle attacks and can inspect Web URLs for evidence of sensitive data that it can copy and send to the C2 server. Ssler will also attempt to downgrade HTTPS traffic to HTTP to gain access to more sensitive information.

The stage 1 malware has also been updated with a new set of sophisticated server location mechanisms and listening modes to allow the attackers to manually trigger further stage 2 and 3 infections. As stage 1 is persistent on devices it is likely this new capability is a direct response to the Federal Bureau of Investigation's advice to reset VPNFilter-affected devices.


Remediation steps

Type Step

Organisations should ensure their networking and NAS devices are fully updated. Any device suspected of being infected should be rebooted or reset to factory defaults to remove VPNFilter stage 2 and 3. Default credentials should be changed on all affected devices.

Telnet is inherently insecure and has been superseded by several other protocols, including SSH. If Telnet is not required, then TCP port 23 should be closed. If Telnet is required, please ensure:

Additionally, to prevent and detect an infection ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place and password reuse is discouraged.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Last edited: 17 February 2020 12:57 pm