Click to Skip Ad
Closing in...

Russian malware has supposedly infected 500,000 devices worldwide, and an attack is imminent

Published May 23rd, 2018 8:00PM EDT
VPNFilter Malware
Image: imageBROKER/REX/Shutterstock

If you buy through a BGR link, we may earn an affiliate commission, helping support our expert product labs.

Russia is back at it again, security experts say, and by it I mean hacking. Not that Russia ever stops hacking.

But the new threat is so real that various experts have agreed to share details for it to prepare the world, with a heavy emphasis on Ukraine, of what might happen next.

Apparently, Russia has been in preparation mode for quite a while, infecting no less than 500,000 routers and storage devices around the world with sophisticated malware.

The attacks could drop as soon as this week, ahead of the Champions League soccer final set to take place in Kiev, Ukraine. One other possible period is late June when the country celebrates Constitution Day. In the past, and as recent as June 2017 when the NotPetya virus disabled computers in the country and spread around the world, the attacks were launched on Ukraine holidays or days leading up to them.

Cisco’s Talos intelligence unit has “high confidence” that the Russian government is behind the campaign, Reuters reports.

That’s because the software shares code with malware used in previous attacks.

Ukraine’s state security service shares the concern, saying estimating that the large-scale attack could drop before Saturday’s soccer game:

Security Service experts believe that the infection of hardware on the territory of Ukraine is preparation for another act of cyber-aggression by the Russian Federation, aimed at destabilizing the situation during the Champions League final.

What’s interesting is that the infections were discovered in 54 countries, which would make it seem like Ukraine isn’t the real target. But a surge of infections in Ukraine on May 8th convinced Cisco that Russia is going after Ukraine again.

Called VPNFIlter lets hackers access infected computers remotely, and then use them to spy on networks, steal login credentials, launch attacks on other computers and load more malware.

The malware also includes an auto-destruct feature that renders the malware and software on infected devices inoperable.

If you think Russia doesn’t use the cyber tools at its disposal to interfere with a country like Ukraine, this light Wired reading from last June should come in handy.

Russia has vigorously denied accusations that it’s conducting large hacking operations around the world, or that it’s trying to interfere with elections. If the VPNFilter attack is indeed triggered, we can probably expect more denials.

Chris Smith Senior Writer

Chris Smith has been covering consumer electronics ever since the iPhone revolutionized the industry in 2008. When he’s not writing about the most recent tech news for BGR, he brings his entertainment expertise to Marvel’s Cinematic Universe and other blockbuster franchises.

Outside of work, you’ll catch him streaming almost every new movie and TV show release as soon as it's available.