Hardware

VPNFilter malware is the reason the FBI recommends resetting all our routers

Table of contents:

Anonim

Whenever we have talked about security in our equipment, about the privacy of our data, we have made reference to the treatment that they make in third-party companies or in our equipment, for which we have always taken collation having a good antivirus. The problem is that the threat, the gateway, is usually another

The router is the weakest link in the chain on many occasions We can protect it with different options and configuration improvements, but when the threat comes from well-designed _malware_ groups, we can do little.And that is what the FBI statement seems to indicate, recommending restarting a series of _routers_ globally.

A threat coming from Russia

The reason appears to be a threat that arrives from Russia in the form of _malware_ under the name VPNFilter. A problem that has already affected more than 500,000 routers in the last few days.

VPNFilter's way of proceeding is, according to what they say, effective and simple. Attacks devices to turn them into bots, which can be controlled remotely to launch coordinated mass attacks. In this way they can spread to other routers and even render them useless. For now these are the models susceptible to being infected:

  • Linksys E1200
  • Linksys E2500
  • Linksys WRVS4400N
  • Mikrotik RouterOS for Cloud Core Routers: Versions 1016, 1036, and 1072
  • etgear DGN2200
  • etgear R6400
  • etgear R7000
  • etgear R8000
  • etgear WNR1000
  • etgear WNR2000
  • QNAP TS251
  • QNAP TS439 Pro
  • QNAP NAS devices running QTS software
  • TP-Link R600VPN
"

These are the models that may be under threat but apparently they are not the only ones and from the United States Federal Bureau of Investigation recommend resetting all routers and improve passwords especially in the case of those that are weak. To do this, simply turn the equipment off and on or use the reset button. But if this is enough for us, we can always follow the advice that CISCO has launched: reset the router to the factory state to leave it as fresh out of the box, although be careful, you will lose all the configuration that you have carried out unless you have a backup."

The origin of VPNFilter is, according to the FBI, in the groups of Russian _hackers_ Fancy Bear and APT28 and had an origin. Causing a computer crash during the 2018 Champion League Final held in Ukraine, a country that does not have good relations with Russia. So much so and such are the suspicions that the Kremlin has denied being behind the attack.

Source | WCCftech

Hardware

Editor's choice

Back to top button