This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
It is distributed through a multi-stage process, with the first stage being delivered to devices using publicly known exploits or default credentials. This stage, which is able to persist through reboots, will then connect with a command and control (C2) server using a number of redundant mechanisms to download the second stage. This second stage is able to exfiltrate data, execute commands and disable infected devices by overwriting critical firmware using the 'kill' or 'exec' commands. Third stage modules can also be downloaded to add further capabilities to the second stage. At present there are two known stage 3 modules; a packet sniffer for collecting network traffic and another which allows the stage 2 malware to communicate using the Tor network, although it is highly probable other modules exist.
Due to the nature of the infected devices VPNFilter will have access to all data that is transferred or stored within an affected network. The ability to disable devices can also be performed simultaneously, raising the possibility of whole networks being disabled at once. Disabled devices are likely to be unrecoverable, requiring full replacement in most cases.
Threat updates
| Date | Update |
|---|---|
| 6 Jun 2018 |
Further details regarding VPNFilter have been disclosed including new third-stage modules and a larger list of targeted devices. Ssler (or essler) is a new third-stage module able to intercept and manipulate all port 80 traffic passing through a device. It will then inject malicious JavaScript payloads in order to perform man-in-the-middle attacks and can inspect Web URLs for evidence of sensitive data that it can copy and send to the C2 server. Ssler will also attempt to downgrade HTTPS traffic to HTTP to gain access to more sensitive information. The stage 1 malware has also been updated with a new set of sophisticated server location mechanisms and listening modes to allow the attackers to manually trigger further stage 2 and 3 infections. As stage 1 is persistent on devices it is likely this new capability is a direct response to the Federal Bureau of Investigation's advice to reset VPNFilter-affected devices. |
Remediation steps
| Type | Step |
|---|---|
|
Organisations should ensure their networking and NAS devices are fully updated. Any device suspected of being infected should be rebooted or reset to factory defaults to remove VPNFilter stage 2 and 3. Default credentials should be changed on all affected devices. Telnet is inherently insecure and has been superseded by several other protocols, including SSH. If Telnet is not required, then TCP port 23 should be closed. If Telnet is required, please ensure:
Additionally, to prevent and detect an infection ensure that:
|
Last edited: 17 February 2020 12:57 pm