{"id":263487,"date":"2018-06-07T09:30:16","date_gmt":"2018-06-07T07:30:16","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=263487"},"modified":"2018-06-07T09:53:42","modified_gmt":"2018-06-07T07:53:42","slug":"all-the-routers-affected-by-vpnfilter-malware","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/263487-all-the-routers-affected-by-vpnfilter-malware.html","title":{"rendered":"All the routers affected by VPNFilter malware"},"content":{"rendered":"<p>In May,\u00a0<a href=\"https:\/\/www.symantec.com\/blogs\/threat-intelligence\/vpnfilter-iot-malware\" target=\"_blank\" rel=\"noopener\"><strong>Symantec warned<\/strong><\/a> about new malware, known as VPNFilter, which targets routers and network-attached storage devices.<\/p>\n<p>VPNFilter can knock out and kill infected devices, and unlike most IoT threats, it can survive a reboot.<\/p>\n<p>VPNFilter has various malicious capabilities, which include spying on traffic routed through the device.<\/p>\n<p>\u201cIts creators appear to have a particular interest in SCADA industrial control systems, creating a module which specifically intercepts Modbus SCADA communications,\u201d said Symantec.<\/p>\n<p>Good news is that the malware does not appear to scan and indiscriminately infect every vulnerable device.<\/p>\n<hr \/>\n<h3 class=\"my-4\">VPNFilter<\/h3>\n<p>Cisco Talos recently <a href=\"https:\/\/blog.talosintelligence.com\/2018\/06\/vpnfilter-update.html\" target=\"_blank\" rel=\"noopener\"><strong>discovered<\/strong><\/a> that VPNFilter was targeting more routers and NAS devices than initially thought, and has additional capabilities.<\/p>\n<p>It said VPNFilter is capable of infecting enterprise and small office and home office routers from ASUS, D-Link, Huawei, Linksys, MikroTik, Netgear, TP-Link, Ubiquiti, Upvel, and ZTE.<\/p>\n<p>The malware can also infect and make it possible to attack QNAP NAS devices.<\/p>\n<div class=\"mybb_table\">\n<div class=\"table-responsive\"><table class=\"table\" border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"7\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" colspan=\"4\" bgcolor=\"#000066\"><span style=\"color: #ffffff;\"><strong>Devices affected by VPNFilter<\/strong><\/span><\/td>\n<\/tr>\n<tr>\n<td bgcolor=\"#F3F3F3\">ASUS<\/td>\n<td bgcolor=\"#F3F3F3\"><strong>D-Link<\/strong><\/td>\n<td bgcolor=\"#F3F3F3\"><strong>Linksys<\/strong><\/td>\n<td bgcolor=\"#F3F3F3\"><strong>TP-Link<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"160\">ASUS RT-AC66U<\/td>\n<td width=\"160\">D-Link DES-1210-08P<\/td>\n<td width=\"160\">Linksys E1200<\/td>\n<td width=\"160\">TP-Link R600VPN<\/td>\n<\/tr>\n<tr>\n<td>ASUS RT-N10<\/td>\n<td>D-Link DIR-300<\/td>\n<td>Linksys E2500<\/td>\n<td>TP-Link TL-WR741ND<\/td>\n<\/tr>\n<tr>\n<td>ASUS RT-N10E<\/td>\n<td>D-Link DIR-300A<\/td>\n<td>Linksys E3000<\/td>\n<td>TP-Link TL-WR841N<\/td>\n<\/tr>\n<tr>\n<td>ASUS RT-N10U<\/td>\n<td>D-Link DSR-250N<\/td>\n<td>Linksys E3200<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>ASUS RT-N56U<\/td>\n<td>D-Link DSR-500N<\/td>\n<td>Linksys E4200<\/td>\n<td bgcolor=\"#F3F3F3\"><strong>Huawei<\/strong><\/td>\n<\/tr>\n<tr>\n<td>ASUS RT-N66U<\/td>\n<td>D-Link DSR-1000<\/td>\n<td>Linksys RV082<\/td>\n<td>Huawei HG8245<\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td>D-Link DSR-1000N<\/td>\n<td>Linksys WRVS4400N<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><\/td>\n<\/tr>\n<tr>\n<td bgcolor=\"#F3F3F3\"><strong>Ubiquiti<\/strong><\/td>\n<td bgcolor=\"#F3F3F3\"><strong>ZTE<\/strong><\/td>\n<td bgcolor=\"#F3F3F3\"><strong>Upvel<\/strong><\/td>\n<td bgcolor=\"#F3F3F3\"><strong>QNAP<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Ubiquiti NSM2<\/td>\n<td>ZTE Devices ZXHN H108N<\/td>\n<td>Upvel Devices &#8211; unknown models<\/td>\n<td>QNAP TS251<\/td>\n<\/tr>\n<tr>\n<td>Ubiquiti PBE M5<\/td>\n<td colspan=\"2\"><\/td>\n<td>QNAP TS439 Pro<\/td>\n<\/tr>\n<tr>\n<td colspan=\"3\"><\/td>\n<td>Other QNAP NAS devices running QTS software<\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" colspan=\"2\" bgcolor=\"#F3F3F3\"><strong>MikroTik<\/strong><\/td>\n<td style=\"text-align: center;\" colspan=\"2\" bgcolor=\"#F3F3F3\"><strong>Netgear<\/strong><\/td>\n<\/tr>\n<tr>\n<td>MikroTik CCR1009<\/td>\n<td>MikroTik CCR1016<\/td>\n<td>Netgear DG834<\/td>\n<td>Netgear DGN1000<\/td>\n<\/tr>\n<tr>\n<td>MikroTik CCR1036<\/td>\n<td>MikroTik CCR1072<\/td>\n<td>Netgear DGN2200<\/td>\n<td>Netgear DGN3500<\/td>\n<\/tr>\n<tr>\n<td>MikroTik CRS109<\/td>\n<td>MikroTik CRS112<\/td>\n<td>Netgear FVS318N<\/td>\n<td>Netgear MBRN3000<\/td>\n<\/tr>\n<tr>\n<td>MikroTik CRS125<\/td>\n<td>MikroTik RB411<\/td>\n<td>Netgear R6400<\/td>\n<td>Netgear R7000<\/td>\n<\/tr>\n<tr>\n<td>MikroTik RB450<\/td>\n<td>MikroTik RB750<\/td>\n<td>Netgear R8000<\/td>\n<td>Netgear WNR1000<\/td>\n<\/tr>\n<tr>\n<td>MikroTik RB911<\/td>\n<td>MikroTik RB921<\/td>\n<td>Netgear WNR2000<\/td>\n<td>Netgear WNR2200<\/td>\n<\/tr>\n<tr>\n<td>MikroTik RB941<\/td>\n<td>MikroTik RB951<\/td>\n<td>Netgear WNR4000<\/td>\n<td>Netgear WNDR3700<\/td>\n<\/tr>\n<tr>\n<td>MikroTik RB952<\/td>\n<td>MikroTik RB960<\/td>\n<td>Netgear WNDR4000<\/td>\n<td>Netgear WNDR4300<\/td>\n<\/tr>\n<tr>\n<td>MikroTik RB962<\/td>\n<td>MikroTik RB1100<\/td>\n<td>Netgear WNDR4300-TN<\/td>\n<td>Netgear UTM50<\/td>\n<\/tr>\n<tr>\n<td>MikroTik RB1200<\/td>\n<td>MikroTik RB2011<\/td>\n<td colspan=\"2\"><\/td>\n<\/tr>\n<tr>\n<td>MikroTik RB3011<\/td>\n<td>MikroTik RB Groove<\/td>\n<td colspan=\"2\"><\/td>\n<\/tr>\n<tr>\n<td>MikroTik RB Omnitik<\/td>\n<td>MikroTik STX5<\/td>\n<td colspan=\"2\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n<hr \/>\n<h3 class=\"my-4\">What owners should do<\/h3>\n<p>If you own one of these devices, you should immediately reboot it. This will temporarily remove the destructive component of VPNFilter.<\/p>\n<p>However, if infected, the continuing presence of the malware means the full VPNFilter can be reinstalled by attackers.<\/p>\n<p>Performing a hard reset of the device, which restores factory settings, should wipe it clean and remove all traces of the malware.<\/p>\n<p>Users should also apply the latest available patches to affected devices and ensure that none use default credentials.<\/p>\n<p>Netgear advised its customers to change default passwords and ensure that remote management is turned off.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read:\u00a0<a href=\"https:\/\/mybroadband.co.za\/news\/security\/262331-how-south-african-comedians-lost-r300000-in-email-scam.html\">How South African comedians lost R300,000 in email scam<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>VPNFilter can infect routers from multiple brands.<\/p>\n","protected":false},"author":23,"featured_media":152621,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[37629,411,51451],"class_list":["post-263487","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cisco-talos","tag-symantec","tag-vpnfilter"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/263487"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=263487"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/263487\/revisions"}],"predecessor-version":[{"id":263531,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/263487\/revisions\/263531"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/152621"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=263487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=263487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=263487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}