Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WIFI Malware Using Geolocator...

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    11 Posts 4 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NollipfSenseN
      NollipfSense
      last edited by

      Saw this today in my ISACA SmartBrief on Cybersecurity...interesting indeed!

      https://www.bleepingcomputer.com/news/security/new-whiffy-recon-malware-uses-wifi-to-triangulate-your-location/

      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

      1 Reply Last reply Reply Quote 0
      • AndyRHA
        AndyRH
        last edited by

        @NollipfSense said in WIFI Malware Using Geolocator...:

        https://www.bleepingcomputer.com/news/security/new-whiffy-recon-malware-uses-wifi-to-triangulate-your-location/

        I may have to change my SSIDs, but I am not sure it would help with so many near me.

        https://support.google.com/maps/answer/1725632?hl=en#zippy=%2Chow-do-i-opt-my-access-point-out-of-google-location-services

        o||||o
        7100-1u

        NollipfSenseN 1 Reply Last reply Reply Quote 1
        • NollipfSenseN
          NollipfSense @AndyRH
          last edited by

          @AndyRH said in WIFI Malware Using Geolocator...:

          @NollipfSense said in WIFI Malware Using Geolocator...:

          https://www.bleepingcomputer.com/news/security/new-whiffy-recon-malware-uses-wifi-to-triangulate-your-location/

          I may have to change my SSIDs, but I am not sure it would help with so many near me.

          https://support.google.com/maps/answer/1725632?hl=en#zippy=%2Chow-do-i-opt-my-access-point-out-of-google-location-services

          Yes, I changing mine also...

          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @NollipfSense
            last edited by

            @NollipfSense if you have some device infected with this - not how you think changing your ssid, or opting out of google location services have any effect or do anything.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            NollipfSenseN AndyRHA 2 Replies Last reply Reply Quote 0
            • NollipfSenseN
              NollipfSense @johnpoz
              last edited by

              @johnpoz said in WIFI Malware Using Geolocator...:

              @NollipfSense if you have some device infected with this - not how you think changing your ssid, or opting out of google location services have any effect or do anything.

              No John...just thought to change it to add the _nomap...never one to trust Google.

              pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
              pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

              1 Reply Last reply Reply Quote 0
              • AndyRHA
                AndyRH @johnpoz
                last edited by

                @johnpoz Also to reduce the effectiveness of the malware.

                o||||o
                7100-1u

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @AndyRH
                  last edited by

                  @AndyRH said in WIFI Malware Using Geolocator...:

                  Also to reduce the effectiveness of the malware.

                  Sure ok ;) If you think 1 out of what, how many wifi networks are in your neighborhood?

                  Here is one site were you can lookup such info, they recently hit a billion!

                  wifinetworks.jpg

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  • AndyRHA
                    AndyRH
                    last edited by

                    I get your point. If I did not live within range of about 20 SSIDs I would consider it. If I lived in the country I would.

                    o||||o
                    7100-1u

                    1 Reply Last reply Reply Quote 0
                    • provelsP
                      provels
                      last edited by provels

                      I may be lacking imagination, or just dim, but what does this get the hacker? Just if someone's running open or WEP? And what does Google even gain from providing this service?

                      Peder

                      MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                      BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                      AndyRHA NollipfSenseN 2 Replies Last reply Reply Quote 0
                      • AndyRHA
                        AndyRH @provels
                        last edited by

                        @provels It can give a hacker a physical location. This added to a name allows the scam to include a threat with a location increasing the odds of success. If the "police" call and say they are coming to 123 Any Street to pick up Bob unless you pay the fine now over the phone, it adds to the credibility.
                        I have had the I.R.S. call with the correct name and say I owe them money and I have to arrange payment now. Since I happen to know a phone call is NOT legal notice, I spend time with them, but I never tell them that little fact or that the I.R.S. never refers to themselves as I.R.S. Adding location will frighten people into giving up information they would not normally give.

                        Also, I think this is a low probability attack.

                        o||||o
                        7100-1u

                        1 Reply Last reply Reply Quote 0
                        • NollipfSenseN
                          NollipfSense @provels
                          last edited by

                          @provels said in WIFI Malware Using Geolocator...:

                          what does this get the hacker?

                          Maybe just to know the GPS info of where this WIFI lives...if the hacker lives aboard, maybe it's an invitation to visit...

                          @provels said in WIFI Malware Using Geolocator...:

                          what does Google even gain from providing this service?

                          More info about a potential revenue source for Google to craft and perfect their approach to extracting wealth from client's pocket to fatten their shareholders. Remember, Google is in the business of extracting wealth through behavior modification of those who use its services.

                          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.