This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Similar to most Mirai variant malware, Vermelho uses a hard-coded list of default credentials to gain access to target devices. It will also use exploits for nine vulnerabilities in several Internet-of-Things (IoT) devices to gain access where possible.
Once installed, Vermelho will connect to a command and control server before scanning for new devices to infect. At the time of publication, it appears that Vermelho is not being used for malicious activity. It is likely that the threat actors behind the botnet are attempting to recruit more devices before beginning any operations.
Remediation advice
By default, many IoT devices use insecure protocols or weak credentials. To avoid such devices becoming part of an IoT botnet, organisations should:Remediation steps
| Type | Step |
|---|---|
Additionally, to prevent and detect an infection, ensure that:
|
Last edited: 17 February 2020 12:56 pm