Cyber Alerts
VPNFilter Router Malware
Verified Officially confirmed
Security researcher at CISCO's Talos Intelligence has discovered an advanced widespread use of a sophisticated modular malware system called "VPNFilter".
- First observed
- 29 May 2018
- Last checked
- 31 Jul 2026
- Evidence records
- 1
- Publication state
- Published
What happened?
Current assessment
Security researcher at CISCO's Talos Intelligence has discovered an advanced widespread use of a sophisticated modular malware system called "VPNFilter".
Why it matters
Denial of service in which affected devices will be unusable, therefore will cause the Internet to be inaccessible.
Who is affected?
Affected products and groups
No affected entity has been safely confirmed in the structured record yet.
What should you do now?
Actions from official guidance
For technical teams
- We advise members of the public who are using the affected routers & network-attached storage (NAS) to do the following: Official source
- Apply the latest available patches to affected devices and ensure that none use default credentials. If infected, reset them to factory defaults and reboot them in order to remove the potentially destructive, non-persistent stage 2 and stage 3 malware. Turn off remote management feature in your router. Official source
Which sources support it?
Evidence and official sources
-
NACSA / NC4 Alerts and AdvisoriesOfficial sourceVPNFilter Router Malware
Security researcher at CISCO's Talos Intelligence has discovered an advanced widespread use of a sophisticated modular malware system called "VPNFilter".
Published 29 May 2018 · Retrieved 31 Jul 2026