Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In this case the ‘CVE-2017-8225’ vulnerability was used to penetrate the GoAhead device and, after infecting a target machine, that same target started to look for other devices to infect. | Check Point Researchers have discovered a brand new Botnet, dubbed ‘IoTroop’, evolving and recruiting IoT devices at a far greater pace and with more potential damage than the Mirai botnet of 2016.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
As sending the malicious code to each device individually would be a large and time consuming task, it is much easier to have each infected device spreading the malicious code to other similar devices themselves. This method of attack is considered a propagation attack.
As sending the malicious code to each device individually would be a large and time consuming task, it is much easier to have each infected device spreading the malicious code to other similar devices themselves. This method of attack is considered a propagation attack.
A global network of millions of hacked IoT devices can be used for a variety of purposes — such as serving as a sort of distributed proxy or anonymity network...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoTroop is an IoT botnet that hijacks unsecured consumer devices such as routers, TVs, DVRs, and IP cameras to launch DDoS attacks. It is notable for its use of the Lua engine, allowing rapid updates and adaptation to new vulnerabilities.
A newly identified IoT botnet that propagates by exploiting vulnerabilities in internet-connected devices such as wireless IP cameras and routers, recruiting them into a distributed network likely intended for large-scale disruptive attacks such as DDoS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.