ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Report
Search
Home > List all groups > List all tools > List all groups using tool VPNFilter

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: VPNFilter

NamesVPNFilter
CategoryMalware
TypeBackdoor, Botnet, Worm
Description(Talos) For several months, Talos has been working with public- and private-sector threat intelligence partners and law enforcement in researching an advanced, likely state-sponsored or state-affiliated actor's widespread use of a sophisticated modular malware system we call 'VPNFilter.' We have not completed our research, but recent events have convinced us that the correct way forward is to now share our findings so that affected parties can take the appropriate action to defend themselves.
Information<https://blog.talosintelligence.com/2018/05/VPNFilter.html>
<https://blog.talosintelligence.com/2018/06/vpnfilter-update.html>
<https://blog.talosintelligence.com/2018/09/vpnfilter-part-3.html>
<https://securelist.com/vpnfilter-exif-to-c2-mechanism-analysed/85721/>
<https://blog.trendmicro.com/trendlabs-security-intelligence/vpnfilter-affected-devices-still-riddled-with-19-vulnerabilities>
<https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophos-VPN-Filter-analysis-v2.pdf>
<https://www.dropbox.com/s/9lkeenhveb3xbkq/Whitepaper%20VPNFilter%20IoT%20botnet%20seized%20by%20the%20FBI.pdf?dl=0>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/elf.vpnfilter>
AlienVault OTX<https://otx.alienvault.com/browse/pulses?q=tag:vpnfilter>

Last change to this tool card: 21 May 2020

Download this tool card in JSON format

Previous: VolatileVenom
Next: VSingle

All groups using tool VPNFilter

ChangedNameCountryObserved

APT groups

XSandworm Team, Iron Viking, Voodoo BearRussia2009-May 2023X
XSofacy, APT 28, Fancy Bear, SednitRussia2004-Feb 2024 HOTX

2 groups listed (2 APT, 0 other, 0 unknown)

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]