Linux.Wifatch

Linux.Wifatch is an open-source piece of malware which has been noted for not having been used for malicious actions, instead attempting to secure devices from other malware.[2]

Linux.Wifatch
Aliases
Author(s)The White Team
Operating system(s) affectedLinux
Written inPerl[2]

Linux.Wifatch operates in a manner similar to a computer security system and updates definitions through its Peer to Peer network and deletes remnants of malware which remain.[3]

Linux.Wifatch has been active since at least November 2014.[4] According to its authors the idea for Linux.Wifatch came after reading the Carna paper.[5] Linux.Wifatch was later released on GitLab by its authors under the GNU General Public License on October 5, 2015.[6]

Linux.Wifatch affects multiple architectures. ARM accounts for 83%, MIPS accounts for 10%, and SH4 accounts for 7%.[2]

Operation

Linux.Wifatch's primary mode of infection is to log into devices using weak or default telnet credentials.[2][4] Once infected, Linux.Wifatch removes other malware and disables telnet access, replacing it with the message "Telnet has been closed to avoid further infection of this device. Please disable telnet, change telnet passwords, and/or update the firmware."[2]

gollark: Hmm, on the one hand I want this "x6.lc" domain because it is short and sounds cool but on the other I would probably never use it for anything but an overengineered URL shortener.
gollark: It's a pickup line which is *probably* meant to imply perfection, but of course does not.
gollark: Ah yes, Pareto optimality.
gollark: Shame I can't get .re.
gollark: Ah, another registrar offers stuff for a mere £16/year.

See also

References

  1. Schick, Shane (October 6, 2015). "Linux.Wifatch: The Router Virus That May Be Secretly Defending You From Other Malware". Security Intelligence. Archived from the original on 7 December 2016. Retrieved 7 December 2016.
  2. Ballano, Mario (1 Oct 2015). "Is there an Internet-of-Things vigilante out there?". Symantec. Retrieved 14 November 2016.
  3. Das, Samburaj (October 2, 2015). "Linux.Wifatch: Vigilante Hacker Infects Routers with Malware to Fight Bad Malware". hacked.com. Retrieved 14 November 2016.
  4. Kovacs, Eduard (October 7, 2015). "Developers of Mysterious Wifatch Malware Come Forward". securityweek.com. Retrieved 15 November 2016.
  5. "linux.wifatch". The White Team. October 5, 2015. Retrieved 15 November 2016.
  6. Cimpanu, Catalin (Oct 7, 2015). "Creators of the Benevolent Linux.Wifatch Malware Reveal Themselves". Softpedia. Retrieved 14 November 2016.
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.