EILMELDUNGEN LIVE
🕵️ SicherheitslückenAI Found Its Own Vulnerability(24.08.2026 um 21:00 Uhr)
⚠️ Malware / Trojaner / VirenApplying Zero Trust Principles to Agents - Kieran Human - ASW #397(25.08.2026 um 11:00 Uhr)
🕵️ SicherheitslückenWhat If Nobody Has Exploited It Yet?(26.08.2026 um 00:00 Uhr)
⚠️ Malware / Trojaner / VirenWhat If Ransomware Never Encrypts Anything?(26.08.2026 um 16:54 Uhr)
🕵️ SicherheitslückenHacking All The Devices, with AI? - Rob Allen - PSW #941(27.08.2026 um 23:00 Uhr)
⚠️ Malware / Trojaner / VirenLegitimate Tools Became Attack Tools(28.08.2026 um 00:00 Uhr)
🕵️ SicherheitslückenWhen The Protocol Is The Vulnerability(28.08.2026 um 16:00 Uhr)
🎥 PodcastsBHIS - Talkin' Bout [infosec] News 2026-08-31(28.08.2026 um 17:13 Uhr)
🕵️ SicherheitslückenAI Found Its Own Vulnerability(24.08.2026 um 21:00 Uhr)
⚠️ Malware / Trojaner / VirenApplying Zero Trust Principles to Agents - Kieran Human - ASW #397(25.08.2026 um 11:00 Uhr)
🕵️ SicherheitslückenWhat If Nobody Has Exploited It Yet?(26.08.2026 um 00:00 Uhr)
⚠️ Malware / Trojaner / VirenWhat If Ransomware Never Encrypts Anything?(26.08.2026 um 16:54 Uhr)
🕵️ SicherheitslückenHacking All The Devices, with AI? - Rob Allen - PSW #941(27.08.2026 um 23:00 Uhr)
⚠️ Malware / Trojaner / VirenLegitimate Tools Became Attack Tools(28.08.2026 um 00:00 Uhr)
🕵️ SicherheitslückenWhen The Protocol Is The Vulnerability(28.08.2026 um 16:00 Uhr)
🎥 PodcastsBHIS - Talkin' Bout [infosec] News 2026-08-31(28.08.2026 um 17:13 Uhr)
24 Personen lesen diesen Beitrag gerade 1 Tag Serie
AI Executive Briefing • Auf den Punkt gebracht Quick Intel
  • Kernaussage: Die neuesten Sicherheitsanalysen und Intelligence-Erkenntnisse im direkten Branchen-Kontext.
  • Bedeutung für die Praxis: Strategische Einordnung für SecOps, DevOps, Administratoren und Entscheider.
  • Empfohlene Mitigation: Sofortige Überprüfung der betroffenen Endpunkte und Einspielen empfohlener Patches.
8 🕛 kürzlich 20 Min Lesezeit 29 Leser online ️ CVE-RADAR
0

MMD-0026-2014 - Router Malware Warning | Reversing an ARM arch ELF AES.DDoS (China malware)

Cyber Threat & Vulnerability Dossier CVSS 5.8 MEDIUM EPSS 96.4%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
️ Im CVE-Radar öffnen
↗ Quelle (blog.malwaremustdie.org)
🔬 IoC Intelligence (3 Indikatoren erkannt)
0bb68bd65d94f61b7b20117b99d8526c182[.]254[.]180[.]241182[.]254[.]180[.]0
🗣️ Stimme:
📑 Inhaltsübersicht

Sticky notes, the latest infection report is below tweet:

)

The background

It is one of our active project to monitor the China origin ELF DDoS'er malware threat. The growth is very rapid nowadays, MMD detected 5 variants is active under almost 15 panels scattered in China network. I am quite active in supporting the team members of this project, so recently almost everyday I reverse ELF files between 5-10 binaries. They are not aiming servers with x32 or x64 architecture but the router devices that runs on Linux too. In some cases I found the FreeBSD variant.

In this story I faced an ARM architecture binary, which I found it interesting so I decided to share it here. The reason is because, practically: it was designed to work in ARM router with minimizing a well-known Linux malware with DDoS functions/features, that I also previously posted some in here --->[] [] [], to specifically infect ARM (router) devices, and this binary is trying to convince that it is a WindowsHelp binary :D , and ,specifically: from my reverse engineering point of view, ARM & "thumb" assembly are interesting.
Why I know it is aiming for router is because, the way to use internet to connect directly to remote global IP, the method used to grab data using specific location in the embedded device, and the trace of sources used during the compilation of the malware itself.

The malware

As usual, China actor(s) serves their malware binary under "specific panel", and this binary is spotted among with other Linux/Elknots malware. So as you can see it was served from Sept 10th and is having 4 downloads (including me, one time)
]

Packer

Let's check, I went to the EP point (0x2f118) and start to do the stuff I usually do, with noted..we have to be very patient with the ARM or THUMB assembly since they have larger steps for simple operation than Intel processor.

;-- entry0:
0x0002f118 adr r12, off_2f104
0x0002f11c ldmia r12, {r1,r2,r10,r11,lr}
0x0002f120 add r10, r10, r12
0x0002f124 add r11, r11, r12
0x0002f128 mov r0, r2
0x0002f12c sub r9, r12, r1
0x0002f130 add r1, r1, #0x1000
0x0002f134 mov r3, #0
0x0002f138 stmfd sp!, {r0-r3,lr}
0x0002f13c mov r2, #7
0x0002f140 ldr r3, [r12,#0x10]
0x0002f144 mov r5, #0
0x0002f148 mov r4, 0xffffffff
0x0002f14c orr r3, r3, #0x10
0x0002f150 mov r7, #0xc0
0x0002f154 svc 0
0x0002f158 cmn r0, #0x1000
0x0002f15c bcs loc_0x02fbd0
[...]
..following the registers value and in r1 we will find the value that can tell what is happening:
0x0002fbd0  mov  r2, #0x1e
0x0002fbd4 adr r1, aprot_execprot_ ; ""PROT_EXEC|PROT_WRITE failed.\n""
0x0002fbd8 mov r0, #2
0x0002fbdc mov r7, #4
0x0002fbe0 svc 0
This value may ring your bells too :). ok this ELF is protected, with/for what? I look from its DCB data from where it was called and clarifying the answer:
0x0002FBF0 aProt_execProt_ DCB "PROT_EXEC|PROT_WRITE failed.",0xA,0
0x0002FC0E DCB 0xA,0
0x0002FC10 aInfoThisFileIs DCB 0x24,"Info: This file is packed with the UPX executable packer http:/"
0x0002FC10 DCB "/upx.sf.net ",0x24,0xA,0
0x0002FC5F aIdUpx3_91Copyr DCB 0x24,"Id: UPX 3.91 Copyright (C) 1996-2013 the UPX Team. All Rights R"
0x0002FC5F DCB "eserved. ",0x24,0xA,0
0x0002FCAB DCB 0x0 ;; here goes the table..
0x0002FCAC DCD 0x9A8, 0x5F9, 0x500E, 0x6C00031A, 0x942C5302, 0x18D063CB
0x0002FCAC DCD 0x49382EE, 0xD185E779, 0x57399E2E, 0xD24C892F, 0x1003EA02
0x0002FCAC DCD 0x6A5A70C9, 0x2F701D6A, 0x6D0D9A7, 0xD2EC6754, 0x95ECE49
[...] [...]
Oh, silly me.. it is a UPX, but, is it common and not modded one? So I went back to check the hex snapshot, to confirm..
00000000  7f 45 4c 46 01 01 01 03  00 00 00 00 00 00 00 00  |.ELF............|
00000010 02 00 28 00 01 00 00 00 18 f1 02 00 34 00 00 00 |..(.........4...|
00000020 00 00 00 00 02 00 00 04 34 00 20 00 02 00 28 00 |........4.(.|
00000030 00 00 00 00 01 00 00 00 00 00 00 00 00 80 00 00 |................|
00000040 00 80 00 00 b1 82 02 00 b1 82 02 00 05 00 00 00 |................|
00000050 00 80 00 00 01 00 00 00 24 0c 00 00 24 0c 0d 00 |........$...$...|
00000060 24 0c 0d 00 00 00 00 00 00 00 00 00 06 00 00 00 |$...............|
00000070 00 80 00 00 93 cc 51 fc 55 50 58 21 b4 11 0d 17 |......Q.UPX!....|
00000080 00 00 00 00 58 64 08 00 58 64 08 00 d4 00 00 00 |....Xd..Xd......|
Since I know that some malware actors is really (enjoying to ) watch this blog too (smile). I don't want to be specific on this, but from reading the hex above we can recognize the originality of this UPX, which it is. Otherwise you have patch it to depack, sample a way to depack the custom UPX is in here-->[
This is just unbelievable, seeking further to figure what is this, I found the complete set of data for this "fake process" which is a self explanatory:

The VirusTotal's link is here-->[]

Conclusion & additional notes

It is up to you to defend your own router. As you can see no AV can detect these malware, it's over a week being there now. Please check your router user interface, make sure you are using the latest updates/firmware and make sure that your setting is correct and unchanged. Being skeptical during checking your router/gateway layer is very recommendable, and if you find anything unusual/suspicious please analyze it WHY and try not to let it go until you find a satisfactory answer for it. If you find it work and having no problem, backup the setting and save it right away.

" so please be noted NOT to put those as equals.

— Hendrik Adrian (@unixfreaxjp) ] The router version of ELF DDoS + backdoor malware is also spotted in the MIPS architercture, analysis is here-->[]. The older version of the ARM ELF DDoS'er malware spotted is also available here-->[ that router is aimed by < Tsunami/Kaiten IRC/

— MalwareMustDie, NPO (@MalwareMustDie) ], that:
"..discovered critical security vulnerabilities in numerous small office/home office (SOHO) routers and wireless access points. These vulnerabilities allow a remote attacker to take full control of the router's configuration settings; some allow a local attacker to bypass authentication directly and take control. "

As an illustration, ISE shows a matrix of vulnerability vectors for the evaluated known routers:
! Tango down report of OP

— MalwareMustDie, NPO (@MalwareMustDie) September 14, 2014

Stay safe, friends! #MalwareMustDie!

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf blog.malwaremustdie.org.
↗ Original-Artikel auf blog.malwaremustdie.org lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
49 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Community-Einschätzung (Live): 48 Stimmen
🟢 Gering: 45% 🟡 Beobachten: 35% 🔴 Akut: 20%

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 43%
🟡 In Evaluierung 23%
🟢 Keine Auswirkung 15%
Spannende Innovation 19%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
1 Quelle
Industry that built the problem offers to sell you the solution
1 Quelle
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Ähnliche Beiträge
🔍 Verwandte News

Ähnliche Beiträge zu MMD-0026-2014 - Router Malware Warning | Reversing an ARM arch ELF AES.DDoS (China malware)

Thematisch verwandte Begriffe: MMD00262014, Router, Malware, Warning

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...