FBI tells router users to reboot now to kill malware infecting 500k devices
1–10 of 299 posts
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#2Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#3Why does EU (for example) authorities not warning their citizens ?
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#4Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#5Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
What about a factory reset? (by pressing on the pinhole button for a few secs)
Correction: according to the original report a reset will mitigate the stage 2 and 3 attack only
Source: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#6How comes that this kind of information seems to only alerte US officials ? Is it targeted only on US soil ? I really doubt that. Why does EU (for example) authorities not warning their citizens ?
Maybe the FBI works closer to manufacturers or victims? I’ve had a freind who got some Wordpress he managed sites infected. He was able to trace it back to a professor in Turkey and call the FBI. The FBI came and interviewed him.
[1]https://www.interpol.int/News-and-media/News/2015/N2015-038
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#7Antivirus provider Symantec issued its own advisory Wednesday that identified the targeted devices as:
Linksys E1200
Linksys E2500
Linksys WRVS4400N
Netgear DGN2200
Netgear R6400
Netgear R7000
Netgear R8000
Netgear WNR1000
Netgear WNR2000
QNAP TS251
QNAP TS439 Pro
TP-Link R600VPN
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#8Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#9Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
https://arstechnica.com/information-technology/2018/05/fbi-s...
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#10Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.