Threat Intelligence

9/26/2018
04:35 PM
50%
50%

VPNFilter Evolving to Be a More Dangerous Threat

VPNFilter malware is adding capabilities to become a more fully-featured tool for threat actors.

Malware writers are finding greater efficiencies by reusing older code families. That explains why VPNFilter — the attack that caused the FBI to recommend that everyone in the US reset their cable modem — is showing up with new capabilities and payloads.

In a new report, Talos says that its researchers have found seven new third-stage VPNFilter modules that add significant new functionality. The new capabilities include including an expanded ability to move laterally between endpoints on a network, data filtering, and multiple encrypted tunnels to mask command-and-control and data exfiltration traffic.

In the conclusion of the report, Talos offers information both worrying and soothing to security professionals. On the one hand, researchers list the new capabilities and point out that these are accompanied by new obfuscation routines, making it more difficult to find the more dangerous malware.

On the other hand, "it appears that VPNFilter has been entirely neutralized since we and our international coalition of partners (law enforcement, intelligence organizations, and the Cyber Threat Alliance) countered the threat earlier this year."

However, Talos cautions against becoming complacent. "[We] know that the actor behind VPNFilter is extremely capable and driven by their mission priorities to continually maneuver to achieve their goals," according to the report. "The sophisticated nature of this framework further illustrates the advanced capabilities of the threat actors making use of it, as well as the need for organizations to deploy robust defensive architectures to combat threats such as VPNFilter."

Read more here.

 

 

Black Hat Europe returns to London Dec. 3-6, 2018, with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:20:56 PM
Sophistication?
The sophisticated nature of this framework further illustrates the advanced capabilities of the threat actors making use of it Sophistication of threats are unimaginable, they are getting very advanced in every way.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:18:32 PM
neutralized?
it appears that VPNFilter has been entirely neutralized Piece of a good news abound among many bad news.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:17:02 PM
Encrypted tunnels
The new capabilities include including an expanded ability to move laterally between endpoints on a network, data filtering, and multiple encrypted tunnels to mask command-and-control and data exfiltration traffic. This new capabilities are poring new threats obviously.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:15:24 PM
Re: custom essay writing service
it's one of the dangerous threat I agree. It needs to be neutralized quite soon.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:13:55 PM
VPNFilter
I thought we are already done with this, why is tho is coming back.
nomjuok
50%
50%
nomjuok,
User Rank: Apprentice
9/27/2018 | 1:11:46 AM
custom essay writing service
it's one of the dangerous threat i heard in the news that the strange happend to the actor. so now days ther is no safety for any one i think by hearing this kind news i was amazed and worried.  so  its good for sharing such a wonderful news to us so that we could also no about these statements.
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8396
PUBLISHED: 2019-02-17
A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while repacking an HDF5 file, aka "Invalid write of size 2."
CVE-2019-8397
PUBLISHED: 2019-02-17
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_close_real in H5T.c.
CVE-2019-8398
PUBLISHED: 2019-02-17
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_get_size in H5T.c.
CVE-2019-8400
PUBLISHED: 2019-02-17
ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.
CVE-2019-7399
PUBLISHED: 2019-02-17
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.