HomeSecurityIoT devices are being attacked by overprotective malware

IoT devices are being attacked by overprotective malware

A new malware is infecting Internet of Things (IoT) devices, which in theory is not actually a piece of malware, because it does nothing bad to the infected devices, but instead protects against further infections.
This Batman of the malware family was detected by Symantec under the name Linux.Wifatch, and it specifically targets WiFi routers, IP cameras, surveillance systems and other devices with an Internet connection.
The infection carried out by Wifatch brute forces easy-to-guess and default Telnet credentials and then, instead of filtering data for its own benefit or adding the device to a DDoS botnet, the malware starts cleaning the device and creating basic protection measures.
Symantec has not seen any such malicious activity carried out by Wifatch since it first saw its action back in 2014, but it does not rule out future suspicious activity.
Currently, after infecting IoT devices, Wifatch begins performing a series of goodwill gestures such as terminating Telnet access, updating firmware, and sometimes leaving a message on the administrator console, asking the legitimate owner of the device to change their password to a more secure one.

IoT devices are being attacked by overprotective malware
Additionally, the malware removes other known malware families if it finds them on the device, and in the case of infecting Dahua DVR CCTV systems, it also launches a custom module that reboots the CCTV system every week. This process is done to remove any malware that may infect the system, one reboot is more than enough to clear the device’s memory of such threats.
Linux.Wifatch is written in Perl and as Symantec researchers pointed out, the source code is not protected from any reverse engineering. The malware’s creator even left a message in the source code, in the form of a quote from Richard Stallman, a famous software freedom activist. The message reads:
“To any NSA and FBI agents reading my email: please consider that defending the U.S. Constitution against all enemies, domestic or foreign, requires you to follow Snowden’s example.”

IoT devices are being attacked by overprotective malware
While this seems like a vigilante effort to protect devices exposed to malicious attacks, let's not rule out the possibility that it could be an alpha or beta version of a much more powerful malware family currently undergoing a testing phase.
Its owner could easily weaponize Wifatch at any time, as Symantec says it has found backdoors in the malware's code, which are protected by cryptographic signatures.
The backdoor would allow the malware's owner to send instructions to the malware at any time and make it download new modules, other malware payloads, while all cryptographic signatures protect its code from being taken over by other attackers.
Currently, Wifatch has infected IoT devices running on ARM architectures, and has been detected in China, Brazil, Mexico, India, Vietnam, Italy, and Turkey.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS