← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2015-01.md
Imported-content SHA-256
ad3a2eb5e460f88bca0cbe5d09fe0e8a36180021a335f4707fa07aaefc4d773d
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 January 2015 |
| Platform | Quiet Systems |
| Series | DKSR-M-2015-01 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

First in-window named backdoor aimed at a civilian UAS flight computer. It rides already-public open Wi-Fi and telnet on Parrot AR.Drone.

### Key judgments

1. **[Assessment — High confidence]** 27 January 2015 first press day. Demonstrated target: Parrot AR.Drone ARM Linux.
2. **[Assessment — High confidence]** No CVE. No vendor advisory found.
3. **[Uncertainty]** Author claim of generality to other ARM Linux civilian drones — not independently confirmed.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Sasi: Maldrone backdoor on Parrot AR.Drone

*Event / publication dates: 27 January 2015 (Forbes, The Hacker News, Security Affairs)*

| Field | Value |
| --- | --- |
| Component | software |
| Product | Parrot AR.Drone (ARM Linux). Only AR.Drone was demonstrated. |
| CVE / advisory | no CVE |
| Patch | none found as a vendor advisory |
| Exploit status | public writeup |
| Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 |

**Verified record — [Fact — B2] Forbes 27 Jan 2015 https://www.forbes.com/sites/thomasbrewster/2015/01/27/malware-takes-down-drone/ · The Hacker News https://thehackernews.com/2015/01/MalDrone-backdoor-drone-malware.html · Security Affairs https://securityaffairs.com/32767/hacking/maldrone-malware-for-drones.html**

**Exposure.** Unauthenticated host access and a persistent backdoor on the flight computer. Act plus persistence.

**Intelligence assessment.** [Assessment — High confidence] Press day and AR.Drone as the demonstrated target. [Uncertainty] Cross-SKU generality.

**Opportunity.** Same open-AP baseline as Pleban 2014. Watch Full Disclosure / Nullcon (February) and DEF CON 23.

**LRRK relevance.** Control Fabric. Act.

**Confidence.** High on date and target. Low on “every ARM Linux drone.”

## Forward indicators

1. Full Disclosure note and Nullcon talk (February 2015).
2. Satterfield DEF CON 23 IoT Village (August 2015).

> **Collection integrity.** One malware line. Not padded. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>