VPNFilter

S1010

Malware.View on attack.mitre.org

About this malware

VPNFilter is a multi-stage, modular platform with versatile capabilities to support both intelligence-collection and destructive cyber attack operations. VPNFilter modules such as its packet sniffer ('ps') can collect traffic that passes through an infected device, allowing the theft of website credentials and monitoring of Modbus SCADA protocols. VPNFilter was assessed to be replaced by Sandworm Team with Cyclops Blink starting in 2019.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1561.001
Disk Content Wipe

VPNFilter has the capability to wipe a portion of an infected device's firmware.

Groups that use it1

Campaigns0

None recorded.

References3

  1. Carl Hurd March 2019 Open source
    Carl Hurd 2019, March 26 VPNFilter Deep Dive Retrieved. 2019/03/28
  2. NCSC CISA Cyclops Blink Advisory February 2022 Open source
    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.
  3. William Largent June 2018 Open source
    William Largent 2018, June 06 VPNFilter Update - VPNFilter exploits endpoints, targets new devices Retrieved. 2019/03/28

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.