Security experts are warning of a new malware campaign (VPNFilter) that targets half a million home routers around the world, with a particular focus on Ukraine.

Cisco Talos announced the discovery of a sophisticated malware called VPNFilter, claiming that there are correlations with the well-known BlackEnergy malware, which is linked to Kremlin hackers.
"While this is not absolute, we have observed that VPNFilter infects routers located in Ukraine, using some Command And Control (C2) servers located in the country," Cisco said.
The malware itself has already infected at least 500,000 SOHO (Small Office Home Office) routers from Linksys, MikroTik, NETGEAR, and TP-Link in 54 countries, as well as some QNAP NAS storage devices.
"The types of devices targeted by hackers are difficult to protect. They are often located at the network perimeter, without an intrusion protection system (IPS) and typically do not have antivirus software installed," Cisco.
This malware has many capabilities since it can corrupt infected devices, covering the traces of attackers, steal credentials typed on a website, and monitor Modbus SCADA protocols.
It is unclear whether the campaign is linked to the attacks on the UK and US governments last month, but a statement from the US Department of Justice on Wednesday attributed the VPNFilter malware campaign to the notorious Russian group APT28.
In the meantime, Cisco is urging ISPs and owners of infected devices to reset them to factory settings and immediately update them with new patches.
