Executive Summary
VPNFilter is a modular router and firewall malware that steals credentials via packet sniffing, monitors industrial protocols, and can overwrite firmware to cause destructive failure. Operated by a state‑backed group, it evolves rapidly into newer variants such as Cyclops Blink. Organizations must update device firmware promptly and monitor network traffic for anomalous C2 communications.
Enhanced Description
VPNFilter is a sophisticated, multi‑stage malware platform engineered to compromise and weaponize network infrastructure devices such as routers, firewalls, and other Linux‑based appliances. Its modular architecture allows attackers to deploy distinct components – for example the packet‑sniffer module ('ps'), which passively captures all traffic traversing the infected device, providing attackers with exposed credentials (HTTP/HTTPS cookies, FTP passwords) and even proprietary industrial protocols like Modbus used in SCADA systems. Subsequent modules can perform destructive operations, such as overwriting critical firmware or deleting log files to erase forensic evidence, thereby transforming an initially espionage‑focused infection into a full‑blown sabotage tool. The malware communicates over standard web protocols (HTTPS/HTTP) with a remote command and control infrastructure that issues update commands and instructs additional modules to load. Analysts have linked later iterations of the threat to the Russian Sandworm Cyber Group, specifically a derivative known as Cyclops Blink, indicating ongoing evolution and state‑level backing. Because VPNFilter can remain dormant while silently collecting data for months, its impact on operational continuity is significant; discovered devices often suffer from impaired network services, degraded performance, or complete loss of functionality after malicious firmware writes have taken effect.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the core operational capabilities—network sniffing, credential theft, and destructive firmware modification—because these have been documented in multiple independent reports. However, exact deployment timelines, frequency of use, and variant distribution remain unclear due to limited public visibility on infected device quantities.
VPNFilter is a multi-stage, modular platform with versatile capabilities to support both intelligence-collection and destructive cyber attack operations. VPNFilter modules such as its packet sniffer ('ps') can collect traffic that passes through an infected device, allowing the theft of website credentials and monitoring of Modbus SCADA protocols. (Citation: William Largent June 2018) (Citation: Carl Hurd March 2019) VPNFilter was assessed to be replaced by Sandworm Team with Cyclops Blink starting in 2019.(Citation: NCSC CISA Cyclops Blink Advisory February 2022)