Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

VPNFilter was a 2018 malware threat to routers and network-attached storage (NAS), not a newly discovered 2026 outbreak. Cisco Talos’s June 2018 follow-up broadened the list of devices known to be affected and added detail on how compromised network equipment could inspect or manipulate traffic and help attack devices behind it. The case also has a defined timeline: the FBI and Department of Justice disrupted part of the botnet in May 2018, and a later joint government advisory described Cyclops Blink as a replacement framework.

What made VPNFilter more concerning after its initial disclosure?

Talos publicly disclosed VPNFilter on May 23, 2018, describing a multi-stage malware framework targeting small-office/home-office (SOHO) routers and NAS devices. Talos estimated at least 500,000 infected devices in at least 54 countries at the time. That is a historical estimate from 2018, not a current infection count.

The concern grew as investigators learned more about both the range of potentially affected devices and the malware’s modular capabilities. Its design could support surveillance and traffic handling, and later-discovered modules could use compromised network equipment as a foothold for attacks against devices on the network behind it.

Which devices were on the affected list?

Talos’s initial report named networking devices from Linksys, MikroTik, NETGEAR and TP-Link, as well as QNAP NAS devices. Its June 2018 follow-up added ASUS, D-Link, Huawei, Ubiquiti, UPVEL and ZTE, along with additional models. Ars Technica reported at the time that the known model list grew from 16 to 71 or more following the update. Talos’s initial report and the contemporary account of the June update provide the historical context.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

A brand name alone does not establish that a particular router or NAS is affected. The historical list is not a current device-support or infection database, and the available reporting does not establish whether any specific reader’s device is infected. Check the exact model and hardware revision against the manufacturer’s security notices and support guidance.

How did the stages and capabilities work?

VPNFilter was not a single, fixed payload. Talos described a staged framework in which an initial component could persist across a reboot and later components supplied additional functions. The capabilities below reflect findings published at different points in 2018, not a promise that every infected device had every module.

Rank #2
Omada ER707-M2, Multi-Gigabit VPN Route
  • 【Flexible Port Configuration】1 2.5Gigabit WAN Port + 1 2.5Gigabit WAN/LAN Ports + 4 Gigabit WAN/LAN Port + 1 Gigabit SFP WAN/LAN Port + 1 USB 2.0 Port (Supports USB storage and LTE backup with LTE dongle) provide high-bandwidth aggregation connectivity.
  • 【High-Performace Network Capacity】Maximum number of concurrent sessions – 500,000. Maximum number of clients – 1000+.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【Highly Secure VPN】Supports up to 100× LAN-to-LAN IPsec, 66× OpenVPN, 60× L2TP, and 60× PPTP VPN connections.
  • 【5 Years Warranty】Backed by our 5-years warranty and free technical support from 6am to 6pm PST Monday to Fridays
Component or finding What Talos reported When established
Stage one Persistence across reboot, helping the infection survive the removal of later components. Initial Talos report, May 2018.
Stage two Collection, command-and-control communication and data exfiltration; some samples could overwrite device firmware destructively. Initial Talos report, May 2018.
Stage three Plugins including packet sniffing and Tor-related functionality. Initial Talos report, May 2018.
Additional stage-three modules Seven additional modules, including filtering, encrypted tunneling and exploitation of endpoints from compromised network devices. Talos follow-up, September 2018.

The endpoint-exploitation capability mattered because a router or NAS sits between outside networks and the devices using it. A compromised network device could potentially inspect or manipulate traffic and provide a route toward other equipment behind it. Talos’s September 2018 follow-up describes the additional modules.

What did investigators say about Russian links?

The attribution record developed over time and should not be reduced to a single clue. In its May 2018 report, Talos noted code overlap with BlackEnergy and a concentration of infections in Ukraine, while explicitly cautioning that the observations were not definitive attribution. DOJ later described VPNFilter as controlled by the Sofacy Group and listed APT28, Sandworm, Fancy Bear and other aliases. A 2022 joint advisory from UK and US agencies attributes Sandworm to Russia’s GRU. These statements come from distinct sources and points in the investigation; the early code overlap alone is not proof of who operated VPNFilter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
TP-Link ER7206, Multi-WAN Professional Wired Gigabit VPN Router
  • 【Flexible Port Configuration】1 Gigabit SFP WAN Port + 1 Gigabit WAN Port + 2 Gigabit WAN/LAN Ports plus1 Gigabit LAN Port. Up to four WAN ports optimize bandwidth usage through one device.
  • 【Increased Network Capacity】Maximum number of associated client devices – 150,000. Maximum number of clients – Up to 700.
  • 【Integrated into Omada SDN】Omada’s Software Defined Networking (SDN) platform integrates network devices including gateways, access points & switches with multiple control options offered – Omada Hardware controller, Omada Software Controller or Omada cloud-based controller(Contact TP-Link for Cloud-Based Controller Plan Details). Standalone mode also applies.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【SDN Compatibility】For SDN usage, make sure your devices/controllers are either equipped with or can be upgraded to SDN version. SDN controllers work only with SDN Gateways, Access Points & Switches. Non-SDN controllers work only with non-SDN APs. For devices that are compatible with SDN firmware, please visit TP-Link website.

Sources: Talos’s initial analysis, the Department of Justice announcement, and the joint NCSC/CISA/NSA/FBI advisory.

Was VPNFilter disrupted, and does rebooting remove it?

In May 2018, the FBI and DOJ seized a command-and-control domain under court order as part of an effort to disrupt the botnet. DOJ said rebooting could remove stage two temporarily, but stage one persisted and could enable reinfection. A reboot alone was therefore not a reliable permanent cleanup method.

Rank #4
Sale
TP-Link Tri-Band BE9700 WiFi 7 Router (Archer BE600)
  • 𝐍𝐞𝐱𝐭-𝐆𝐞𝐧 𝐖𝐢-𝐅𝐢 𝟕 - Optimize performance on latest WiFi 7 laptops and devices, like the iPhone 16 Pro, Samsung Galaxy S24 Ultra, and PS5 Pro with the latest WiFi 7 technology with Multi-Link Operation, Multi-RUs, 4K-QAM, and up to 320 MHz channels.◇△
  • 𝟕-𝐒𝐭𝐫𝐞𝐚𝐦, 𝐁𝐄𝟗𝟕𝟎𝟎 𝐓𝐫𝐢-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝟕 𝐒𝐩𝐞𝐞𝐝𝐬 - Delivers smooth 4K/8K streaming, immersive AR/VR gaming, and blazing-fast downloads with speeds up to 5,765 Mbps on the 6 GHz band, 2,882 Mbps on the 5 GHz band, and 1,032 Mbps on the 2.4 GHz band.⌂
  • 𝐌𝐚𝐱𝐢𝐦𝐢𝐳𝐞𝐝 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 - Up to 2,600 sq. ft. coverage for up to 120 devices at a time. 6 optimally positioned antennas and Beamforming technology focus Wi-Fi signals toward hard-to-cover areas for stronger coverage-—ideal for those seeking the best WiFi router for large homes.
  • 𝟏𝟎 𝐆𝐛𝐩𝐬 𝐏𝐨𝐫𝐭 𝐟𝐨𝐫 𝐌𝐮𝐥𝐭𝐢-𝐆𝐢𝐠𝐚𝐛𝐢𝐭 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐯𝐢𝐭𝐲 - Features 1x 10 Gbps WAN/LAN port, 1x 2.5 Gbps WAN/LAN port, and 3x 2.5 Gbps LAN ports. Integrate with a multi-gig modem for fast, wired gig+ internet.
  • 𝐎𝐮𝐫 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐦𝐦𝐢𝐭𝐦𝐞𝐧𝐭 - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.

At the time, Talos recommended factory-resetting and rebooting affected SOHO routers and NAS devices, then working with manufacturers to install current firmware patches. Those were period recommendations, not universal instructions for every device today. If you suspect a device is compromised, identify its exact model and hardware revision and follow the manufacturer’s current security and firmware instructions; resetting or updating it incorrectly can disrupt connectivity or erase settings.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is VPNFilter still an active threat today?

The available sources do not establish a defensible 2026 count of residual VPNFilter infections or a current, model-by-model list of affected devices that remain supported. They also cannot determine whether a particular consumer device is infected. Treat VPNFilter as a serious historical incident, not evidence that a device is currently compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Mikrotik hEX RB750Gr3 5-port Ethernet Gigabit Router
  • hEX also known as RB750Gr3 is a five port Gigabit Ethernet router for locations where wireless connectivity is not required
  • The device has a full size USB port. This new updated revision of the hEX brings several improvements in performance
  • It is affordable, small and easy to use, but at the same time comes with a very powerful dual core 880MHz CPU and 256MB RAM
  • IPsec hardware encryption (~470 Mbps) and The Dude server package is supported, microSD slot on it provides improved r/w speed for file storage and Dude
  • Dimensions: 113x89x28mm; Storage size: 16 MB; Passive PoE (PoE in); PCB temperature monitor, Voltage monitor and Mode button

A later joint advisory says Cyclops Blink appeared to replace VPNFilter and that Sandworm showed limited interest in old VPNFilter footholds after the 2018 disruption. Cyclops Blink is a successor framework described in later reporting; it is not another name for VPNFilter.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.