# Russians hack US routers - FBI advises users to reboot now

**URL:** <https://boards.straightdope.com/t/russians-hack-us-routers-fbi-advises-users-to-reboot-now/814830>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [May 26, 2018, 12:13am UTC](https://boards.straightdope.com/t/russians-hack-us-routers-fbi-advises-users-to-reboot-now/814830 "2018-05-26T00:13:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sunny\_Daze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunny_daze/32/438_2.png) [@Sunny\_Daze](https://boards.straightdope.com/u/Sunny_Daze)\
**Post date:** [May 26, 2018, 12:13am UTC](https://boards.straightdope.com/t/russians-hack-us-routers-fbi-advises-users-to-reboot-now/814830/1 "2018-05-26T00:13:49Z")

</div>

From [arstechnica](https://arstechnica.com/information-technology/2018/05/fbi-tells-router-users-to-reboot-now-to-kill-malware-infecting-500k-devices/) (and other sources), new malware from Russia has been found on an estimated American 500K devices.

> [@](#):
>
> The FBI is advising users of consumer-grade routers and network-attached storage devices to reboot them as soon as possible to counter Russian-engineered malware that has infected hundreds of thousands devices.

> [@](#):
>
> The detailed report said the malware infected more than 500,000 devices made by Linksys, Mikrotik, Netgear, QNAP, and TP-Link. Known as VPNFilter, the malware allowed attackers to collect communications, launch attacks on others, and permanently destroy the devices with a single command.

The FBI issued the following statement on what to do to protect yourself:

> [@](#):
>
> The FBI recommends any owner of small office and home office routers reboot the devices to temporarily disrupt the malware and aid the potential identification of infected devices. Owners are advised to consider disabling remote management settings on devices and secure with strong passwords and encryption when enabled. Network devices should be upgraded to the latest available versions of firmware.

Note that this is not a permanent fix. The malware is not completely removed if your device is infected. It will attempt to reinstall. This is a stopgap intended to buy the government and security experts time to fix this.

---

<div class="post-metadata">

**Author:** ![Buttercup\_Smith](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/buttercup_smith/32/473_2.png) [@Buttercup\_Smith](https://boards.straightdope.com/u/Buttercup_Smith)\
**Post date:** [May 26, 2018, 1:19am UTC](https://boards.straightdope.com/t/russians-hack-us-routers-fbi-advises-users-to-reboot-now/814830/2 "2018-05-26T01:19:27Z")

</div>

Would a router from a provider like Comcast be affected?

---

<div class="post-metadata">

**Author:** ![Mr.Bill](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@Mr.Bill](https://boards.straightdope.com/u/Mr.Bill)\
**Post date:** [May 27, 2018, 1:01am UTC](https://boards.straightdope.com/t/russians-hack-us-routers-fbi-advises-users-to-reboot-now/814830/3 "2018-05-27T01:01:01Z")

</div>

I read this and my question is how does rebooting one’s router:

> [@](#):
>
> aid the potential identification of infected devices

?

Does it stop working altogether, flash a message on my computer screen “Hey, your router is infected with the new Russian malware”, or what?

Also, assuming I identify that my router is infected, what then? Is there a solution other than replacing the router?

This is not completely academic, as my router is on the list of potentially affected devices.

---

<div class="post-metadata">

**Author:** ![Sunny\_Daze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunny_daze/32/438_2.png) [@Sunny\_Daze](https://boards.straightdope.com/u/Sunny_Daze)\
**Post date:** [May 27, 2018, 1:24am UTC](https://boards.straightdope.com/t/russians-hack-us-routers-fbi-advises-users-to-reboot-now/814830/4 "2018-05-27T01:24:25Z")

</div>

> [@Buttercup\_Smith](#):
>
> Would a router from a provider like Comcast be affected?

Yes, any consumer router made by the manufacturers listed (just easier to reboot at this point).

> [@Mr.Bill](#):
>
> I read this and my question is how does rebooting one’s router:
> 
> ?
> 
> Does it stop working altogether, flash a message on my computer screen “Hey, your router is infected with the new Russian malware”, or what?
> 
> Also, assuming I identify that my router is infected, what then? Is there a solution other than replacing the router?
> 
> This is not completely academic, as my router is on the list of potentially affected devices.

I would need to do some more digging into technical bulletins to understand exactly how infected machines are detected on networks, but I am happy to do so if you would like. Cisco issued a warning earlier last week identifying the issue, so there are indicators. (ETA - it could stop working, according to the alert. That is one of the risks.)

The best way to interpret where we are now that is that they need more time to understand this, and rebooting all routers removes the most dangerous parts of the virus from infected routers. It will leave some parts on your router, however, if you are infected. Longer term, the fix is that router manufacturers, the government, and security companies will work together to provide firmware patches. You’ll need to upgrade your firmware when those are available. This is the solution. Replacing the router won’t remove the vulnerability unless it has the new firmware.
