#vpnfilter
DOJ/FBI have been increasingly frisky over the last seven years using subpoena and similar power to actively dismantle adversary infrastructure - two examples for RU being VPNFilter and Cyclops Blink networks. These are ambitious efforts that really do "impose cost" that are now potentially at risk.
March 2, 2025 at 11:15 PM
AA22-054A: New Sandworm Malware Cyclops Blink Replaces VPNFilter

ift.tt/eNGCgt8
New Sandworm Malware Cyclops Blink Replaces VPNFilter | CISA
Official websites use .gov A .gov website belongs to an official government organization in the United States.
ift.tt
January 29, 2025 at 4:40 PM
AA22-054A: New Sandworm Malware Cyclops Blink Replaces VPNFilter

ift.tt/eNGCgt8
New Sandworm Malware Cyclops Blink Replaces VPNFilter | CISA
Official websites use .gov A .gov website belongs to an official government organization in the United States.
ift.tt
January 29, 2025 at 4:40 PM
AA22-054A: New Sandworm Malware Cyclops Blink Replaces VPNFilter

ift.tt/gheACcT
New Sandworm Malware Cyclops Blink Replaces VPNFilter | CISA
Official websites use .gov A .gov website belongs to an official government organization in the United States.
ift.tt
January 29, 2025 at 4:40 PM
You Can't Patch Burnout: VPNFilter, the Defender's Toll, and the Playbook Nobody Writes-Joe Marshall www.youtube.com/watch?v=vGGQ...
You Can't Patch Burnout: VPNFilter, the Defender's Toll, and the Playbook Nobody Writes-Joe Marshall
In 2018, Cisco Talos exposed VPNFilter, half a million compromised routers, a destructive state-sponsored botnet, a disclosure that made global headlines. I helped take it down. Then I spent seven…
www.youtube.com
September 22, 2026 at 11:12 AM
This looks like the same kind of MITM that the VPNFilter guys used, but on a much softer class of targets - apparently they can get what they want from the captive portal instead of having to remotely replace firmware.
Russian state hackers have been taking over the Wi-Fi sign-in pages travelers use in hotels and conference venues, then pushing fake update malware and stealing the tokens that unlock corporate email. Microsoft says the campaign has been running since May.

#APT29 #APT #infosec
Russian hackers hijack hotel Wi-Fi to bug travelers
Nation-State · IntelFusions threat intelligence
www.intelfusions.com
August 10, 2026 at 12:13 PM
Is Your Router Vulnerable to VPNFilter Malware? via @PCMag
November 12, 2024 at 1:15 AM
Internet-of-Things (IoT) Security: Developments in VPNFilter and Emergence of Torii Botnet - Security News - Trend Micro GB...
November 18, 2024 at 12:05 PM
Tecnicamente essa teria sido a outra vez que "salvei o mundo", após informar o óbvio e ao relatar o que foi feito contra mim, então guarde bem essa informação
...
#Hardwarehacking
#Tempestsdr
#Raiosx
#Energiadirigida
#Stalking
#vpnfilter
#bluejacking
February 18, 2025 at 10:49 AM
Chaque fois plus sophistiqué ..
New VPNFilter malware targets at least 500K networking devices worldwide
November 21, 2024 at 9:09 AM
Day 76 #100DaysofYARA - looking for likely embedded certificates in PE and ELF files!

ELF families include favorites:
WellMess
MATA Framework
VPNFilter

https://github.com/g-les/100DaysofYARA/blob/main/100_days_of_yara.yar
December 1, 2024 at 5:05 AM
uncommon:

.comment.SUSE.OPTs (MESSAGETAP)
.llvm_addrsig (Kobalos)
.upx0 / .upx1 (KEYPLUG)
nocommon (Defray)
.SUNW_version (LightBasin)
.data.rel.ro.local (WINNTI)
.note.tag (TSCookie, Kobalos)
__libc_subfreeres (PLEAD, TSCookie, CASPER, MATA, PenguinTurla, VPNFilter)
December 1, 2024 at 5:00 AM
similar to PE's, ELF have section blocks of executable code, data, tables, and other stuff, with goodies such as name

as the S1 homies noted, AcidRain and VPNFilter stg3 had identical section names (and thus identical .shstrtab sections)

Lets dump out all ELF sect names!
December 1, 2024 at 4:49 AM
Hackers infect 500,000 consumer routers all over the world with malware https://arstechnica.com/?post_type=post&p=1313593
Hackers infect 500,000 consumer routers all over the worl...
VPNFilter can survive reboots and contains destructive “k...
arstechnica.com
February 15, 2025 at 4:45 AM
Be safe. Please reboot your routers. Thanks. FBI tells router users to reboot now to kill malware infecting 500k devices | Ars Technica

jrblz.info/2L5Ktuw
FBI tells router users to reboot now to kill malware infecting 500k devices
Feds take aim at potent VPNFilter malware allegedly unleashed by Russia.
jrblz.info
December 10, 2024 at 3:05 AM
VPNFilter malware can destroy infected consumer routers on command! Are we sure these guys are actually villains? Things like that could be the cure the completely broken way our devices are [not] patched today! https://t.co/T6Z2uWXeNW
May 24, 2018 at 3:22 PM
#Security Advisory for VPNFilter Malware on Some Ro... - #NETGEAR Communities
November 19, 2024 at 7:19 PM