The Trojan Horse Malware & Password “Cracking” Ecosystem Targeting Industrial Operators
ID: a82158b0-bff1-53e8-bc0a-8202e182f9ce
STIX ID: report--a82158b0-bff1-53e8-bc0a-8202e182f9ce
Feed Name: Dragos Blog
Dragos discovered a criminal ecosystem selling trojanized PLC/HMI/project-file “password cracking” tools that exploit a firmware flaw in Automation Direct DirectLogic 06 (CVE-2022-2003) to reveal passwords and drop Sality malware; the malware establishes a P2P botnet, persists via file/kernel infection and autorun propagation, hijacks cryptocurrency clipboard addresses, and can interfere with AV updates. The report reproduces the serial exploit (and over Ethernet), lists many affected vendors/products, notes responsible disclosure and firmware fixes, and warns engineers to avoid running untrusted tools and to seek vendor/Dragos assistance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
