Death Botnet
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Death is using a known exploit of fourteen vulnerabilities in AVTech's firmware to compromise their range of IP cameras and local & network video recorders (DVR/NVR). Once Death is installed on a device it is granted full permissions and begins scanning for other vulnerable devices using custom Shodan search.
The author of the malware, referred to as EliteLands online, has stated that the botnet was originally intended to be used for distributed denial-of-service attacks but is for now only using it to enrol new devices.
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:41 pm