Bushido IoT Botnet
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Bushido uses brute-force attacks as well as several known vulnerabilities to compromise devices. The brute-force attacks use a significantly larger dictionary than older Mirai variants.
Once installed on a device, Bushido will connect to a command and control server over IRC before awaiting further instructions. The Bushido botnet is currently being used to perform smaller-scale DDoS attacks.
Threat updates
| Date | Update |
|---|---|
| 29 Oct 2018 |
A new DDoS campaign has been observed reselling the Bushido botnet for use by other threat actors. Known as 0x-booter, the campaign is offering both transportation and application layer attacks with volumes up to 500 Gbps. |
Remediation advice
To protect against DDoS attacks, CareCERT recommends organisations should:Remediation steps
| Type | Step |
|---|---|
Should an organisation suspect it is subject to an active DDoS attack, CareCERT recommends that whilst efforts are made to stop the attack and restore service, care should be taken to ensure that the attackers are not using the DDoS attack as a distraction whilst other, potentially more sensitive, systems are exploited. Monitoring of critical systems is recommended, including the use of Host Intrusion Prevention and Detection Systems (HIPS/HIDS) where appropriate. To avoid devices becoming part of an IoT botnet, CareCERT recommends organisations should:
|
Last edited: 17 February 2020 12:39 pm