VPNFilter is a sophisticated multi-stage, modular malware platform targeting internet-connected network infrastructure, primarily small office and home office routers and network-attached storage devices. It infected hundreds of thousands of devices globally in 2018 and is widely attributed to Sandworm, a Russian GRU-linked threat actor. The malware is notable for combining espionage, traffic manipulation, botnet operations, and destructive functionality in a framework designed for long-term compromise of edge devices.
VPNFilter targets a broad range of embedded Linux-based devices from multiple vendors, including routers and NAS appliances. Its architecture supports staged deployment and modular expansion, allowing operators to tailor post-compromise actions. Documented capabilities include interception and manipulation of network traffic, credential and token theft from observed communications, reconnaissance of victim environments, routing modification, and deployment of additional modules. Reported modules include functionality for monitoring industrial control system traffic such as Modbus, anonymizing communications through Tor, and destructive wiping or device-bricking operations.
The malware has been described as both an espionage platform and a pre-positioning capability for disruptive or destructive attacks. It can serve as an ingress point for attacks against downstream systems connected through the compromised device, enabling broader post-exploitation activity inside victim networks. VPNFilter also demonstrated resilience and persistence characteristics that complicated remediation, and simple rebooting was not considered sufficient protection against continued risk without full remediation and firmware updates.
Victimology included routers and NAS devices across at least dozens of countries, with notable concern around activity in Ukraine and the potential impact on critical infrastructure and operational technology environments. Public reporting linked spikes in infections in Ukraine to possible preparation for a larger disruptive operation. Law enforcement and industry disruption efforts in 2018 seized or sinkholed parts of its command-and-control infrastructure, but residual infections persisted on some devices afterward.
VPNFilter is regarded as one of the most advanced IoT malware families publicly exposed, and later Sandworm malware such as Cyclops Blink has been assessed as a successor framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As explained in the advisory, the malware appeared to have emerged as early as June 2019, and was the apparent successor to another Sandworm botnet called VPNFilter, which the Department of Justice disrupted through a court-authorized operation in 2018.
As a side note, the IOCTLs used by this malware also match the ones used by the VPNFilter malware 'dstr' wiper plugin, a malicious tool attributed to Russian GRU hackers...
Cisco Talos first disclosed the existence of VPNFilter on May 23, 2018... The malware’s multi-stage modular platform supported both intelligence-collection and destructive cyber attack operations.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
both the Photobucket accounts and the toknowall.com domain were hosting images in which the IP address of the C2 server, used by the threat actor to issue instructions to the malware were hidden, disguised within the EXIF metadata of the image.
To keep important data within the malware confidential, the malicious code used encryption, implementing the RC4 encryption algorithm.
One particular module contained functionality to identify and monitor Modbus network traffic, a protocol widely used in Industrial Control Systems. | the malware could modify the routing information and create custom destinations for certain traffic; redirecting traffic from the genuine destination to a separate system under the control of the attackers.
Clearly, capturing data, especially usernames and passwords, was one goal of the attack.
One particular module contained functionality to identify and monitor Modbus network traffic, a protocol widely used in Industrial Control Systems. | the malware could modify the routing information and create custom destinations for certain traffic; redirecting traffic from the genuine destination to a separate system under the control of the attackers.
devices in over 100 countries are being scanned on ports 23, 80, 2000, and 8080, which are indicative of additional scanning for vulnerable Mikrotik and QNAP NAS devices.
By March 2018, additional malware samples were discovered that also reached out to Photobucket, and used toknowall.com as a backup in case Photobucket was unavailable.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Router-focused botnet/malware referenced as historical background for SOHO router compromise campaigns.
Mentioned because its stage-three 'dstr' wiper shares some IOCTL wiping-method similarities with the Acid wipers, though the report says the logic differs in detail.
A router-targeting botnet used to communicate with infected routers.
Malware infecting home routers at scale; described here as compromising large numbers of routers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.