iotsecurity (2)

31223369266?profile=RESIZE_400xFortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot.  The name derives from the hardcoded string “evooo1” found in every binary.  While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple

31016876682?profile=RESIZE_400xAt the end of October, during a global disruption of AWS connections, FortiGuard Labs observed malware named “ShadowV2” spreading via IoT vulnerabilities.  These incidents affected multiple countries worldwide and spanned seven different industries.  To date, the malware appears to have been active only during the large-scale AWS outage.  Researchers believe this activity was likely a test run conducted in preparation for future attacks.  The following article provides a detailed analysis of the