Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 23:07:43 UTC Home > List all groups > List all tools > List all groups using tool VPNFilter Tool: VPNFilter Names VPNFilter Category Malware Type Backdoor, Botnet, Worm Description (Talos) For several months, Talos has been working with public- and private-sector threat intelligence partners and law e in researching an advanced, likely state-sponsored or state-affiliated actor's widespread use of a sophisticated modular m system we call 'VPNFilter.' We have not completed our research, but recent events have convinced us that the correct wa to now share our findings so that affected parties can take the appropriate action to defend themselves. Information MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 27 December 2024 Download this tool card in JSON format All groups using tool VPNFilter Changed Name Country Observed APT groups Sandworm Team, Iron Viking, Voodoo Bear 2009-Dec 2024 Sofacy, APT 28, Fancy Bear, Sednit 2004-Apr 2025 2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2b224eef-4ed5-4267-8c56-acd46592cb6d https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2b224eef-4ed5-4267-8c56-acd46592cb6d Page 1 of 1