Skip to main content

BrickerBot PDoS attack

BrickerBot is a Permanent Denial-of-Service (PDoS) cyber-attack that compromises IoT devices to permanently corrupt their storage.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

BrickerBot is a Permanent Denial-of-Service (PDoS) cyber-attack that compromises IoT devices to permanently corrupt their storage.

Threat details

The BrickerBot PDoS attack uses Telnet to remotely brute force vulnerable IOT devices with weak and default passwords.

Upon successful access a device, the BrickerBot bot performs a series of Linux commands crafted to corrupt storage, disrupt Internet connectivity, impede device performance, and delete all files on the device.

Several variants BrickerBot.1 and BrickerBot.2 have been observed in the wild with the latter variant being more sophisticated and using TOR to conceal the location of infected BOTs.


Remediation steps

Type Step
  • Change default IOT device passwords
  • Disable Telnet access to IOT devices (Block Port 23 at your firewall)
  • Monitor firewall and ICT logs for indicators of compromise
  • Use an IPS to detect and block Telnet default credentials

Last edited: 17 February 2020 11:27 am