LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 January 2015 | | Platform | Quiet Systems | | Series | DKSR-M-2015-01 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF First in-window named backdoor aimed at a civilian UAS flight computer. It rides already-public open Wi-Fi and telnet on Parrot AR.Drone. ### Key judgments 1. **[Assessment — High confidence]** 27 January 2015 first press day. Demonstrated target: Parrot AR.Drone ARM Linux. 2. **[Assessment — High confidence]** No CVE. No vendor advisory found. 3. **[Uncertainty]** Author claim of generality to other ARM Linux civilian drones — not independently confirmed. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Sasi: Maldrone backdoor on Parrot AR.Drone *Event / publication dates: 27 January 2015 (Forbes, The Hacker News, Security Affairs)* | Field | Value | | --- | --- | | Component | software | | Product | Parrot AR.Drone (ARM Linux). Only AR.Drone was demonstrated. | | CVE / advisory | no CVE | | Patch | none found as a vendor advisory | | Exploit status | public writeup | | Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 | **Verified record — [Fact — B2] Forbes 27 Jan 2015 https://www.forbes.com/sites/thomasbrewster/2015/01/27/malware-takes-down-drone/ · The Hacker News https://thehackernews.com/2015/01/MalDrone-backdoor-drone-malware.html · Security Affairs https://securityaffairs.com/32767/hacking/maldrone-malware-for-drones.html** **Exposure.** Unauthenticated host access and a persistent backdoor on the flight computer. Act plus persistence. **Intelligence assessment.** [Assessment — High confidence] Press day and AR.Drone as the demonstrated target. [Uncertainty] Cross-SKU generality. **Opportunity.** Same open-AP baseline as Pleban 2014. Watch Full Disclosure / Nullcon (February) and DEF CON 23. **LRRK relevance.** Control Fabric. Act. **Confidence.** High on date and target. Low on “every ARM Linux drone.” ## Forward indicators 1. Full Disclosure note and Nullcon talk (February 2015). 2. Satterfield DEF CON 23 IoT Village (August 2015). > **Collection integrity.** One malware line. Not padded. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>