Hide n' Seek IoT Botnet
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
HNS randomly generates IP addresses and initiates a connection to each potential target. It then attempts to determine the type of target device and select the most suitable compromise method. If located on the same network then HNS sets up a file transfer server for the target to download the malicious code, otherwise it attempts a remote payload delivery method.
About 20,000 IoT devices have been infected at the time of publication. It currently cannot persist on a device after it has been switched off, but it does use multiple anti-tampering techniques. If successful it could steal data, execute malicious code and interfere with a device's operation.
For further information:
Threat updates
| Date | Update |
|---|---|
| 9 May 2018 |
A new version of Hide n' Seek has been observed with the ability to maintain persistence. Once it has successfully infected a device, Hide n' Seek will copy itself to the file location /etc/init.d/ and add itself to the boot process list. Note this method only works when the infection is initiated via telnet, as root privileges are required to access the init.d directory. |
Remediation advice
To prevent and detect infection, ensure that:Remediation steps
CVE Vulnerabilities
Last edited: 17 February 2020 12:44 pm