ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool VPNFilter

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: VPNFilter

NamesVPNFilter
CategoryMalware
TypeBackdoor, Botnet, Worm
Description(Talos) For several months, Talos has been working with public- and private-sector threat intelligence partners and law enforcement in researching an advanced, likely state-sponsored or state-affiliated actor's widespread use of a sophisticated modular malware system we call 'VPNFilter.' We have not completed our research, but recent events have convinced us that the correct way forward is to now share our findings so that affected parties can take the appropriate action to defend themselves.
Information<https://blog.talosintelligence.com/2018/05/VPNFilter.html>
<https://blog.talosintelligence.com/2018/06/vpnfilter-update.html>
<https://blog.talosintelligence.com/2018/09/vpnfilter-part-3.html>
<https://securelist.com/vpnfilter-exif-to-c2-mechanism-analysed/85721/>
<https://blog.trendmicro.com/trendlabs-security-intelligence/vpnfilter-affected-devices-still-riddled-with-19-vulnerabilities>
<https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophos-VPN-Filter-analysis-v2.pdf>
<https://www.dropbox.com/s/9lkeenhveb3xbkq/Whitepaper%20VPNFilter%20IoT%20botnet%20seized%20by%20the%20FBI.pdf?dl=0>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/elf.vpnfilter>
AlienVault OTX<https://otx.alienvault.com/browse/pulses?q=tag:vpnfilter>

Last change to this tool card: 20 May 2020

Download this tool card in JSON format

All groups using tool VPNFilter

ChangedNameCountryObserved

APT groups

 Sofacy, APT 28, Fancy Bear, SednitRussia2004-Jun 2021 HOTX

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key