Skip to main content

IoT Malware Discovered Trying to Attack Satellite Systems of Airplanes, Ships

posted onAugust 10, 2018
by l33tdawg
Daily Mail UK
Credit: Daily Mail UK

Ruben Santamarta was flying from Madrid to Copenhagen in November 2017 on a Norwegian Airlines flight when he decided to inspect the plane's Wi-Fi network security. So he launched Wireshark from his laptop and began monitoring the network.

Santamarta noted "some weird things" happening. First off, his internal IP address was assigned a public, routable IP address, and then, more disconcerting, he suddenly noticed random network scans on his computer. It turned out the plane's satellite modem data unit, or MDU, was exposed and rigged with the Swordfish backdoor, and a router from a Gafgyt IoT botnet was reaching out to the satcom modem on the in-flight airplane, scanning for new bot recruits.

The Internet of Things (IoT) botnet code didn't appear to have infected any of the satcom terminals on that plane or others, according to Santamarta, but it demonstrated how exposed the equipment was to potential malware infections. "This botnet was not prepared to infect VxWorks. So, fortunately, it was no risk for the aircraft," he said.

Source

Tags

Security

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th