Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

9/26/2018
04:35 PM
50%
50%

VPNFilter Evolving to Be a More Dangerous Threat

VPNFilter malware is adding capabilities to become a more fully-featured tool for threat actors.

Malware writers are finding greater efficiencies by reusing older code families. That explains why VPNFilter — the attack that caused the FBI to recommend that everyone in the US reset their cable modem — is showing up with new capabilities and payloads.

In a new report, Talos says that its researchers have found seven new third-stage VPNFilter modules that add significant new functionality. The new capabilities include including an expanded ability to move laterally between endpoints on a network, data filtering, and multiple encrypted tunnels to mask command-and-control and data exfiltration traffic.

In the conclusion of the report, Talos offers information both worrying and soothing to security professionals. On the one hand, researchers list the new capabilities and point out that these are accompanied by new obfuscation routines, making it more difficult to find the more dangerous malware.

On the other hand, "it appears that VPNFilter has been entirely neutralized since we and our international coalition of partners (law enforcement, intelligence organizations, and the Cyber Threat Alliance) countered the threat earlier this year."

However, Talos cautions against becoming complacent. "[We] know that the actor behind VPNFilter is extremely capable and driven by their mission priorities to continually maneuver to achieve their goals," according to the report. "The sophisticated nature of this framework further illustrates the advanced capabilities of the threat actors making use of it, as well as the need for organizations to deploy robust defensive architectures to combat threats such as VPNFilter."

Read more here.

 

 

Black Hat Europe returns to London Dec. 3-6, 2018, with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:20:56 PM
Sophistication?
The sophisticated nature of this framework further illustrates the advanced capabilities of the threat actors making use of it Sophistication of threats are unimaginable, they are getting very advanced in every way.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:18:32 PM
neutralized?
it appears that VPNFilter has been entirely neutralized Piece of a good news abound among many bad news.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:17:02 PM
Encrypted tunnels
The new capabilities include including an expanded ability to move laterally between endpoints on a network, data filtering, and multiple encrypted tunnels to mask command-and-control and data exfiltration traffic. This new capabilities are poring new threats obviously.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:15:24 PM
Re: custom essay writing service
it's one of the dangerous threat I agree. It needs to be neutralized quite soon.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 2:13:55 PM
VPNFilter
I thought we are already done with this, why is tho is coming back.
nomjuok
50%
50%
nomjuok,
User Rank: Apprentice
9/27/2018 | 1:11:46 AM
custom essay writing service
it's one of the dangerous threat i heard in the news that the strange happend to the actor. so now days ther is no safety for any one i think by hearing this kind news i was amazed and worried.  so  its good for sharing such a wonderful news to us so that we could also no about these statements.
Why AI Will Create Far More Jobs Than It Replaces
John DiLullo, CEO, Lastline,  5/14/2019
Baltimore Ransomware Attack Takes Strange Twist
Kelly Jackson Higgins, Executive Editor at Dark Reading,  5/14/2019
Windows 10 Migration: Getting It Right
Kevin Alexandra, Principal Solutions Engineer at BeyondTrust,  5/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11809
PUBLISHED: 2019-05-20
An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector.
CVE-2019-12198
PUBLISHED: 2019-05-20
In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header.
CVE-2019-12185
PUBLISHED: 2019-05-20
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This will allow for PHP files to be written to the web r...
CVE-2019-12184
PUBLISHED: 2019-05-19
There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence, gallery, or chart, as demonstrated by a crafted SRC attribute of an IFRAME element, a different vulnerability than CVE-2019-12136.
CVE-2019-12173
PUBLISHED: 2019-05-18
MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A element. This is different from CVE-2019-12138.