Cyber Alerts

VPNFilter Router Malware

Verified Officially confirmed

Security researcher at CISCO's Talos Intelligence has discovered an advanced widespread use of a sophisticated modular malware system called "VPNFilter".

First observed
29 May 2018
Last checked
31 Jul 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

Security researcher at CISCO's Talos Intelligence has discovered an advanced widespread use of a sophisticated modular malware system called "VPNFilter".

Why it matters

Denial of service in which affected devices will be unusable, therefore will cause the Internet to be inaccessible.

Who is affected?

Affected products and groups

No affected entity has been safely confirmed in the structured record yet.

What should you do now?

Actions from official guidance

For technical teams

  1. We advise members of the public who are using the affected routers & network-attached storage (NAS) to do the following: Official source
  2. Apply the latest available patches to affected devices and ensure that none use default credentials. If infected, reset them to factory defaults and reboot them in order to remove the potentially destructive, non-persistent stage 2 and stage 3 malware. Turn off remote management feature in your router. Official source

Which sources support it?

Evidence and official sources

  1. NACSA / NC4 Alerts and AdvisoriesOfficial source
    VPNFilter Router Malware

    Security researcher at CISCO's Talos Intelligence has discovered an advanced widespread use of a sophisticated modular malware system called "VPNFilter".

    Published 29 May 2018 · Retrieved 31 Jul 2026