A viral vigilante may be keeping an eye on your home router

An old virus affecting routers running Linux appears to be protecting them from other malware infections, Symantec researchers say

An old virus affecting routers and other devices running Linux appears to be acting as a digital vigilante, protecting routers in the dark alleyways of the Internet from other malware infections.

Researchers at Symantec first began tracking Linux.Wifatch on Jan. 12, describing it merely as a "Trojan that may open a back door on the compromised router" and adding a couple of pages of generic advice for removing it and keeping it from infecting other devices

The company subsequently noted that another researcher going by the name l00t_myself had spotted the virus in his home router as long ago as November 2014. He dismissed it as easy to decode and having "stupid coding bugs." He reported via Twitter that he had identified over 13,000 other devices infected with it.

That prompted other researchers to chime in that they too had identified it, variously nicknaming it Reincarna and Zollard -- which was spotted in Internet-connected devices as far back as 2013.

Then things went quiet: The developer of the virus didn't do anything bad with the backdoor access, and the other researchers seemed to lose interest.

Now, though, the Symantec researchers think they've figured out what Linux.Wifatch was up to: It was keeping other viruses out of the devices it had invaded.

That in itself is nothing new: the botnet creators have been known to defend their patch before, fighting off or removing rival malware in order to maintain their botnet's destructive power.

The difference, according to Symantec researcher Mario Ballano, is that Wifatch seems only to be defending, not attacking. "It appeared like the author was trying to secure infected devices instead of using them for malicious activities," he wrote in a blog post Thursday.

Devices infected with Wifatch communicate via their own peer-to-peer network, using it to distribute updates about other malware threats. They don't exchange malicious payloads, and in general the code seems designed to harden, or protect, the infected devices.

For instance, Symantec believes Wifatch infects the devices via telnet, exploiting weak passwords -- but if anyone else, including the device's owner, attempts to connect via telnet, they receive the following message: "Telnet has been closed to avoid further infection of this device. Please disable telnet, change telnet passwords, and/or update the firmware."

It also attempts to remove other well-known router malware.

A further sign of its author's good intentions, Ballano said, is that there is no attempt to hide the malware: the code is not obfuscated, and it even includes debug messages making it easier to analyze.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Peter Sayer

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?