In late May, Cisco researchers discovered a routercalled VPNFilter, which had so far infected more than 500,000 Wi-Fi devices. The routers affected were from companies like TP-Link, Linksys, MikroTik, and Linksys.
According to the latest report, other device companies have also been targeted by the malware. The new targets include ASUS, D-Link, Huawei, Ubiquiti, UPVEL, and ZTE. However, Cisco networking devices remain unaffected, the researchers claim.
The additional discovery concerns a new stage 3 module used to infect web content, as data passes through a network device. It also provides the malware with the capability for man-in-the-middle attacks.
After infecting the router, it first configures iptables to redirect the data flow to the local port and uses the insmod command to load various modules.
Additionally it blocks any outgoing web requests on port 80. Therefore, the data flow can be monitored and manipulated before it reaches the HTTP service.
This development clearly shows that VPNFilter is continuously evolving and its reach has expanded. It also means that VPNFilter remains active, even if you follow the FBI's advice to reboot the router.
You can read more details about the dangerous malware here.
