Skip to main content

Bushido IoT Botnet

First observed in 2018, Bushido is a Mirai-based worm targeting Internet-of-Things (IoT) devices to enrol into a distributed denial-of-service (DDoS) botnet.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

First observed in 2018, Bushido is a Mirai-based worm targeting Internet-of-Things (IoT) devices to enrol into a distributed denial-of-service (DDoS) botnet.

Affected platforms

The following platforms are known to be affected:

Threat details

Bushido uses brute-force attacks as well as several known vulnerabilities to compromise devices. The brute-force attacks use a significantly larger dictionary than older Mirai variants.

Once installed on a device, Bushido will connect to a command and control server over IRC before awaiting further instructions. The Bushido botnet is currently being used to perform smaller-scale DDoS attacks.


Threat updates

Date Update
29 Oct 2018

A new DDoS campaign has been observed reselling the Bushido botnet for use by other threat actors. Known as 0x-booter, the campaign is offering both transportation and application layer attacks with volumes up to 500 Gbps.


Remediation advice

To protect against DDoS attacks, CareCERT recommends organisations should:

Remediation steps

Type Step
  • Use a suitable third-party DDoS mitigation tool.
  • Have a DDoS mitigation plan in place.

Should an organisation suspect it is subject to an active DDoS attack, CareCERT recommends that whilst efforts are made to stop the attack and restore service, care should be taken to ensure that the attackers are not using the DDoS attack as a distraction whilst other, potentially more sensitive, systems are exploited. Monitoring of critical systems is recommended, including the use of Host Intrusion Prevention and Detection Systems (HIPS/HIDS) where appropriate.

To avoid devices becoming part of an IoT botnet, CareCERT recommends organisations should:

  • Review the network security of IoT devices on the estate.
  • Change any IoT device default usernames and passwords.

Last edited: 17 February 2020 12:39 pm