Linux.Wifatch
| Linux.Wifatch | |
|---|---|
| Malware details | |
| Alias | |
| Family | Virus |
| Authors | The White Team |
| Technical details | |
| Platform | Linux |
| Written in | Perl[2] |
Linux.Wifatch is an open-source piece of malware which has been noted for not having been used for malicious actions, instead attempting to secure devices from other malware.[2]
Linux.Wifatch operates in a manner similar to a computer security system and updates definitions through its Peer to Peer network and deletes remnants of malware which remain.[3]
Linux.Wifatch has been active since at least November 2014.[4] According to its authors the idea for Linux.Wifatch came after reading the Carna paper.[5] Linux.Wifatch was later released on GitLab by its authors under the GNU General Public License on October 5, 2015.[6]

Operation
[edit | edit source]Linux.Wifatch's primary mode of infection is by logging into devices using weak or default telnet credentials.[2][4] Once infected, Linux.Wifatch removes other malware and disables telnet access, replacing it with the message "Telnet has been closed to avoid further infection of this device. Please disable telnet, change telnet passwords, and/or update the firmware."[2]
See also
[edit | edit source]- Denial-of-service attack
- BASHLITE – another notable IoT malware
- Linux.Darlloz – another notable IoT malware
- Remaiten – another notable IoT malware
- Mirai – another notable IoT malware
- Hajime (malware) - malware which appears to be similar in purpose to Wifatch
References
[edit | edit source]- ^ a b Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
- ^ a b c d e Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
- ^ Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
- ^ a b Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
- ^ Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
- ^ Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).