← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2020-07.md
Imported-content SHA-256
fc7dd48f635765b092eac056dac4c9a5cd9cbdc059edbc48de50c4f744eb7459
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 July 2020 |
| Platform | Quiet Systems |
| Series | DKSR-M-2020-07 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

Synacktiv and GRIMM publish the GO 4 forced-update and identifier-SDK analysis the same day. DJI calls it hypothetical and says it updated GO 4 on 31 July.

### Key judgments

1. **[Assessment — High confidence]** 23 July 2020. Samples include v4.3.36_200426. Testers used Mavic 2.
2. **[Assessment — High confidence]** Phone-side installer is a kinematic trust path (GEO/NFZ and pairing live here).
3. **[Uncertainty]** Residual risk after the 31 July DJI change — River Loop still saw a custom path in September 2021.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Synacktiv / GRIMM: DJI GO 4 forced update and SDKs

*Event / publication dates: 23 July 2020 (both). DJI statement and claimed GO 4 change 31 July 2020.*

| Field | Value |
| --- | --- |
| Component | software |
| Product | DJI GO 4 Android (v4.3.36_200426, v4.3.25, v4.1.22 among samples) |
| CVE / advisory | no CVE |
| Patch | partial / disputed |
| Exploit status | public writeup; GRIMM validated |
| Taxonomy | CAPEC-186 · ATT&CK ICS T0843 · OWASP IoT I3 · I4 · EMB3D TID-211 |

**Verified record — [Fact — A1] https://synacktiv.com/publications/dji-android-go-4-application-security-analysis · https://grimmcyber.com/dji-privacy-analysis-validation/**

**Exposure.** Forced APK outside Play; Weibo dropper; MobTech IDs (removed by 4.3.36 per Synacktiv). GCS/app on the aircraft control path.

**Intelligence assessment.** [Assessment — High confidence] Four claimed behaviors on GO 4. [Uncertainty] DJI “hypothetical” framing vs independent validation.

**Opportunity.** Passport installer (store vs sideload vs in-app). Watch Pilot (August) and River Loop 2021.

**LRRK relevance.** Control Fabric. Sense (who is on the phone).

**Confidence.** High on publication. Moderate on residual after 31 July.

## Forward indicators

1. Synacktiv Pilot (4 August 2020).
2. River Loop residual (2 September 2021).

> **Collection integrity.** No CVE. Not padded. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>