Skip to main content

JenX IoT Botnet

JenX is a Internet of Things (IoT) botnet that has been seen performing distributed denial-of-service (DDoS) attacks using traffic volumes of up to 300Gbps. The attackers have been offering the use of the botnet as a DDoS-for-Hire-Service.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

JenX is a Internet of Things (IoT) botnet that has been seen performing distributed denial-of-service (DDoS) attacks using traffic volumes of up to 300Gbps. The attackers have been offering the use of the botnet as a DDoS-for-Hire-Service.

Threat details

JenX has be created using code from other botnets like Satori, however JenX does not spread from infected IoT device to other IoT devices like Satori and Mirai. JenX spreads from compromised servers which scan for devices that are vulnerable to the following exploits:


Remediation steps

Type Step
  • Ensure that all IoT devices are kept updated with patches and secure passwords.
  • Ports 37125 and 52869 should be monitored and, if not in use, be disabled.
  • Default credentials and security settings on IoT devices (IP cameras, door sensors, etc) should be altered.


Last edited: 17 February 2020 12:46 pm