Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

1–10 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#2
Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#4
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

What about a factory reset? (by pressing on the pinhole button for a few secs)

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#5
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

What about a factory reset? (by pressing on the pinhole button for a few secs)

A factory reset, according to Cisco, will fix it.

Correction: according to the original report a reset will mitigate the stage 2 and 3 attack only

Source: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#6

How comes that this kind of information seems to only alerte US officials ? Is it targeted only on US soil ? I really doubt that. Why does EU (for example) authorities not warning their citizens ?

I can find some articles about Interpol/Europol taking down botnets.[1] The US and Russia are probably more advanced than the EU in this regard. I wouldn’t put the UK or China too far behind.

Maybe the FBI works closer to manufacturers or victims? I’ve had a freind who got some Wordpress he managed sites infected. He was able to trace it back to a professor in Turkey and call the FBI. The FBI came and interviewed him.

[1]https://www.interpol.int/News-and-media/News/2015/N2015-038

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#7
"There's no easy way to determine if a router has been infected. It's not yet clear if running the latest firmware and changing default passwords prevents infections in all cases."

Antivirus provider Symantec issued its own advisory Wednesday that identified the targeted devices as:

Linksys E1200

Linksys E2500

Linksys WRVS4400N

Netgear DGN2200

Netgear R6400

Netgear R7000

Netgear R8000

Netgear WNR1000

Netgear WNR2000

QNAP TS251

QNAP TS439 Pro

TP-Link R600VPN

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#8
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

> Blindly trusting the FBI

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#9
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

True but it should help since one of the stage 1 C&C’s domain has been seized (by the FBI as you mentioned).

https://arstechnica.com/information-technology/2018/05/fbi-s...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#10
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

If they've seized the C&C domain, can't they push an update that disable the malware?
Post reply on HN