In May 2019, Wapack Labs performed an inventory of recent Mirai specimens on Virus Total. A total of 29K malware specimens were observed during the period spanning from early March to mid-May 2019. A comprehensive indicator list is provided as a companion document to this product.
To read the full article and find an archive of related reporting, follow this link to READBOARD.
WWW.WAPACKLABS.COM
Showing posts with label IoT. Show all posts
Showing posts with label IoT. Show all posts
Thursday, May 23, 2019
Tuesday, November 21, 2017
Reaper IoT Botnet Exploits and Mitigations

TLP AMBER ANNOUNCEMENT:
The Reaper IoT is a recently discovered Internet of Things (IoT) botnet that is proving to be more sophisticated and aggressive than the infamous 2016 Mirai IoT botnet. Despite the large botnet size reported by Tenable, there are very few IoT Reaper specimens available on Virus Total and other malware sharing sites. This is important to note as the number of specimens is often a reflection of the amount of infections. For example, there are currently thousands of Mirai specimens as opposed to a few dozen IoT Reaper specimens available. To date, no Distributed Denial of Service (DDoS) attacks have been observed with the IoT Reaper botnet. Wapack Labs analysts are providing this document as a summary of mitigations and indicators for Reaper malware and observed exploits. Wapack Labs recommends testing of all signatures before deployment...READ MORE
Wapack Labs has cataloged and reported on IoT and botnets in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
This TLP AMBER report is available only to Red Sky Alliance members.
Tuesday, February 7, 2017
Roughnecks v. IoT/SCADA
The oil industry is the latest to recognize the benefits – and the risks – of the Internet of Things (IoT). Increased use of automation and robotics is causing many traditional “Roughneck” jobs to be abolished. IoT-enabled (SCADA) systems control automated oil drilling sites, which drives down both labor costs and human errors, but introduces new risks. Such systems and the devices they are composed of are built for functionality and reliability, not security. “Air gaps” and other protections help, but the same service and maintenance pathways legitimate vendors use to meet service level agreements are also avenues of attack for malicious actors.Wapack Labs has extensively reported on IoT in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.
TLP: AMBER
ACTOR TYPE: (III)
SERIAL: TR-029-2017
COUNTRIES: US
INDUSTRIES: OIL
REPORT DATE: 20170207
Labels:
air gaps,
IoT,
malicious actors,
oil,
SCADA
Subscribe to:
Posts (Atom)
