BrickerBot PDoS attack
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The BrickerBot PDoS attack uses Telnet to remotely brute force vulnerable IOT devices with weak and default passwords.
Upon successful access a device, the BrickerBot bot performs a series of Linux commands crafted to corrupt storage, disrupt Internet connectivity, impede device performance, and delete all files on the device.
Several variants BrickerBot.1 and BrickerBot.2 have been observed in the wild with the latter variant being more sophisticated and using TOR to conceal the location of infected BOTs.
Remediation steps
Last edited: 17 February 2020 11:27 am