Depends on the target, id consider something like Stuxnet to be top-notch given:
- Delivery
- Target resources (another state)
- Target defenses (I like to think that the iranians had good security)
- Stealthiness
- Target architecture. Its easier to write something for Android (for which we have the OS open sourced) than for siemens PLC
But as others say, you wouldn't want to advertise your exploit as top-notch, as it will bring unwanted attention
Nothing, because blackhat activity disqualifies itself from such a label. Recognition is actively withheld since it'd encourage some bad actors. Same reason malicious software is always given a different name even if one can be found in it.
Depends on the target, id consider something like Stuxnet to be top-notch given: - Delivery - Target resources (another state) - Target defenses (I like to think that the iranians had good security) - Stealthiness - Target architecture. Its easier to write something for Android (for which we have the OS open sourced) than for siemens PLC
But as others say, you wouldn't want to advertise your exploit as top-notch, as it will bring unwanted attention
This thing has been in the wild since 2024, so it had a good run.
It looks pretty bespoke, so there are likely other variants.
Also targeting the anti-virus executable is a smart way to hide. I don't think this backdoor was cheap to develop.
Nothing, because blackhat activity disqualifies itself from such a label. Recognition is actively withheld since it'd encourage some bad actors. Same reason malicious software is always given a different name even if one can be found in it.