Куда я попал?
VPNFilter
VPNFilter is a multi-stage, modular platform with versatile capabilities to support both intelligence-collection and destructive cyber attack operations. VPNFilter modules such as its packet sniffer ('ps') can collect traffic that passes through an infected device, allowing the theft of website credentials and monitoring of Modbus SCADA protocols. (Citation: William Largent June 2018) (Citation: Carl Hurd March 2019) VPNFilter was assessed to be replaced by Sandworm Team with Cyclops Blink starting in 2019.(Citation: NCSC CISA Cyclops Blink Advisory February 2022)
ID: S1010
Type: MALWARE
Platforms: Windows
Created: 26 Mar 2019
Last Modified: 15 Aug 2024
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1561 | .001 | Disk Wipe: Disk Content Wipe |
VPNFilter has the capability to wipe a portion of an infected device's firmware.(Citation: VPNFilter Router) |
Groups That Use This Software |
||
ID | Name | References |
---|---|---|
G0034 | Sandworm Team |
(Citation: NCSC CISA Cyclops Blink Advisory February 2022) |
References
- Carl Hurd 2019, March 26 VPNFilter Deep Dive Retrieved. 2019/03/28
- NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.
- William Largent 2018, June 06 VPNFilter Update - VPNFilter exploits endpoints, targets new devices Retrieved. 2019/03/28
- Tung, Liam. (2018, May 29). FBI to all router users: Reboot now to neuter Russia's VPNFilter malware. Retrieved March 7, 2024.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.