FBI tells router users to reboot now to kill malware infecting 500k devices
11–20 of 299 posts
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#12How comes that this kind of information seems to only alerte US officials ? Is it targeted only on US soil ? I really doubt that. Why does EU (for example) authorities not warning their citizens ?
It's possible that the models affected by this particular attack aren't sold in other places, or perhaps they are, but are actually still different (enough). Or they are just not widely used.
I say this because govt. organisations have often issued warnings and recommendations like this in similar circumstances, e.g. a while ago some modem-routers widely used in this country were attacked, and a warning very much like this has been issued.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#13Earlier quoted context omitted.
What about a factory reset? (by pressing on the pinhole button for a few secs)
A factory reset, according to Cisco, will fix it. Correction: according to the original report a reset will mitigate the stage 2 and 3 attack only Source: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...
It's not clear how stage 1 installs. Is it into the (hidden) base Linux install in rc.local or whatever, does it get into the bios/firmware of the computer.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#14Glad now have Google WiFi. Most secure consumer router you can get, imo.
I use a peplink, which doesn’t target the “consumer” market. Is that better? Seems impossible to know.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#15Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
If they've seized the C&C domain, can't they push an update that disable the malware?
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#16Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
That's, uh, "reassuring".
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#17Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#18Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
If they've seized the C&C domain, can't they push an update that disable the malware?
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#19Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#20Glad now have Google WiFi. Most secure consumer router you can get, imo.