Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
IT Security VideoPC Security Channel: FBI vs Shiny Hunters: Hacker Group Saga(01.10.2026 um 20:30 Uhr)
••
Sicherheitslücken (CVE)FortiMail-Null-Day: CISA nimmt CVE-2026-104286 in KEV auf(02.10.2026 um 08:40 Uhr)
•
Sicherheitslücken (CVE)Angriffe auf FortiMail-Zero-Day-Lücke beobachtet(02.10.2026 um 08:46 Uhr)
•
IT Security NachrichtenCISO Advantage: Sophos liefert Vorstandsberichte auf Knopfdruck(02.10.2026 um 08:40 Uhr)
•
IT Security NachrichtenNIS2 bleibt für viele Unternehmen eine offene Baustelle(02.10.2026 um 08:50 Uhr)
•
AI & KI NachrichtenOpenAI Alerts More Than 100 Groups About Rogue AI Agent Activity(02.10.2026 um 09:00 Uhr)
•
IT Security NachrichtenZelda: The Wind Waker - native PC-Portierung für Windows verfügbar(02.10.2026 um 08:42 Uhr)
•••
IT Security VideoPC Security Channel: FBI vs Shiny Hunters: Hacker Group Saga(01.10.2026 um 20:30 Uhr)
••
Sicherheitslücken (CVE)FortiMail-Null-Day: CISA nimmt CVE-2026-104286 in KEV auf(02.10.2026 um 08:40 Uhr)
•
Sicherheitslücken (CVE)Angriffe auf FortiMail-Zero-Day-Lücke beobachtet(02.10.2026 um 08:46 Uhr)
•
IT Security NachrichtenCISO Advantage: Sophos liefert Vorstandsberichte auf Knopfdruck(02.10.2026 um 08:40 Uhr)
•
IT Security NachrichtenNIS2 bleibt für viele Unternehmen eine offene Baustelle(02.10.2026 um 08:50 Uhr)
•
AI & KI NachrichtenOpenAI Alerts More Than 100 Groups About Rogue AI Agent Activity(02.10.2026 um 09:00 Uhr)
•
IT Security NachrichtenZelda: The Wind Waker - native PC-Portierung für Windows verfügbar(02.10.2026 um 08:42 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

Youtube virusbtn: Tracking the IoT botnet's bloodline: code footprints don’t lie

Video von Youtube virusbtn auf YouTube: Author: Virus Bulletin - Bewertung: 0x - Views:1 Tracking the IoT botnet's bloodline: code footprints don’t lie…

HD Video
Tracking the IoT botnet's bloodline: code footprints don’t lie
Video abspielen
Beitrag
0
Seite
0
↗ Quelle (youtube.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Author: Virus Bulletin - Bewertung: 0x - Views:1

Tracking the IoT botnet's bloodline: code footprints don’t lie



Presented at the VB2025 conference in Berlin, 24 - 26 September 2025.

↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2025/slides/Slides-Tracking-the-IoT-botnets-bloodline-code-footprints-dont-lie.pdf

↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2025/papers/Tracking-the-IoT-botnets-bloodline-code-footprints-dont-lie.pdf

→ Details: https://www.virusbulletin.com/conference/vb2025/abstracts/tracking-iot-botnets-bloodline-code-footprints-dont-lie/



✪ PRESENTED BY ✪



• Chanbin Jeon (SANDS Lab)

• ChangGyun Kim (SANDS Lab)

• SeungBeom Lim (SANDS Lab)



✪ ABSTRACT ✪



In January 2025, we identified a previously unreported IoT bot named "x86", confirmed to be a variant of the Gafgyt (BASHLITE) family, which had infected over one million IoT devices. Upon execution, the bot connects to a command-and-control server in Germany and sends the message "Joined RebirthReborn As". Unlike typical variants, "x86" lacks propagation features and supports only six hard-coded commands, indicating a simplified operational model.



IoT botnet analysis is increasingly difficult due to widespread code reuse and minor modifications by threat actors to evade detection. Manual analysis methods are insufficient to manage the growing number of variants, highlighting the need for automated techniques to track malware lineage and identify relationships between variants.



To meet this challenge, we introduce a hybrid automated analysis framework that combines function-level embedding vector similarity with Large Language Models (LLMs). Decompiled malware functions are transformed into embedding vectors, with similarity measured using cosine and Euclidean distance. This enables efficient clustering, accurate variant detection, and comprehensive malware genealogy tracking.



Using this technique, we analysed the lineage of "x86" and correlated it with contextual intelligence derived from open-source social channels commonly used by threat actors, including YouTube, Discord, Telegram, Instagram and Twitch. Our investigation revealed a clear evolution from the "qBot" variant, progressing through "Demon" and "Rebirth", to the current "Rebirth Reborn".



We named the threat actor group behind this lineage "CTX-5341", comprising actors such as "SelfRepNeTiS". CTX-5341 has operated through cooperative frameworks and reseller models. One member recently launched a standalone DDoS service, "Eternal Stresser", indicating further fragmentation.



Although "SelfRepNeTiS" reportedly exited the scene around 2022 after selling all related source code, the reappearance of Rebirth Reborn in late 2024 suggests renewed activity or third-party operators. Our framework proved highly effective in tracing this lineage. It can also be adapted to other malware families depending on the structure of the analysis dataset, making it a valuable tool for modern malware investigations.

🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

Bedrohungsgraph · ATT&CK-Mapping · Exploit-Belege
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
3 Knoten · 2 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
14 Taktiken
2 belegte Techniken
T1498TA0040 · Impact
Network Denial of Service
Mitigation: M1037 Filter Network Traffic
Quelle: Kontext-Klassifikation des Artikeltextes
T1071TA0011 · Command and Control
Application Layer Protocol (C2)
Mitigation: M1031 Network Intrusion Prevention & Egress Filtering
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Tracking the IoT botnet's bloodline: code footprints don’t lie

Thematisch verwandte Begriffe: Tracking, botnets, bloodline, code · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag